<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T07:04:59.228-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:8553" version="12" class="vulnerability">
      <metadata>
        <title>HTML Element Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0494"/>
        <description>Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:26.751-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:51.165-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:30.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:46.442-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:06.318-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:21.521-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.559-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:27.730-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8553 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.639-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:37.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8524" version="3" class="vulnerability">
      <metadata>
        <title>SMB Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0021"/>
        <description>Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:57.317-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:30.356-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:19.475-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:20.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8491" version="10" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0245)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0245"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:41.311-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:17.250-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:28.410-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:02.660-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:50.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:45.701-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:05.463-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.446-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.446-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:19.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8491 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:28.487-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:36.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8464" version="12" class="vulnerability">
      <metadata>
        <title>URL Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0027"/>
        <description>The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:39.590-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:19:00.314-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Added checks for Schlwapi.dll" date="2010-02-10T13:06:00.077-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:26.899-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:16.416-04:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.486-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:48.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:47.784-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:04.384-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.822-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.822-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:18.191-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:11.005-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:27.040-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8464 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:28.718-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:36.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Shlwapi.dll version is less than 5.0.3900.7349" test_ref="oval:org.mitre.oval:tst:20440"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Shlwapi.dll version is less than 6.0.2900.3653" test_ref="oval:org.mitre.oval:tst:20970"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Shlwapi.dll version is less than 6.0.2900.5912" test_ref="oval:org.mitre.oval:tst:20936"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="Shlwapi.dll version is less than 6.0.3790.4603" test_ref="oval:org.mitre.oval:tst:20977"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8438" version="3" class="vulnerability">
      <metadata>
        <title>SMB Pathname Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0020"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:54.857-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:25.104-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:14.869-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.915-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.915-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:17.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8424" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Data Analyzer ActiveX Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0252"/>
        <description>The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:10.997-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:23.593-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:13.627-04:00">ACCEPTED</status_change>
            <modified comment="Added additional criteria for Active X control detection." date="2010-06-14T10:40:00.826-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-06-14T10:46:39.917-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:06.002-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.603-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.603-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:16.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:53.249-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:33.271-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E0ECA9C3-D669-4EF4-8231-00724ED9288F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:20990"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E0ECA9C3-D669-4EF4-8231-00724ED9288F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:21016"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{14FD1463-1F3F-4357-9C03-2080B442F503}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27468"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{14FD1463-1F3F-4357-9C03-2080B442F503}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27497"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E9CB13DB-20AB-43C5-B283-977C58FB5754}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27250"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E9CB13DB-20AB-43C5-B283-977C58FB5754}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8378" version="10" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0246)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0246"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0245.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:41.857-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:13.463-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:20.715-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:04.603-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:47.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:44.972-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:03.549-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:52.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:52.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:15.264-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8378 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:28.232-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:35.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8324" version="5" class="vulnerability">
      <metadata>
        <title>Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0018"/>
        <description>Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-12T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:56.446-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:36.628-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:09.040-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:58.415-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:58.415-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:13.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4217 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:21.123-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:34.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.0.2195.7348 or T2embed.dll &lt; 5.0.2195.7348">
            <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7348" test_ref="oval:org.mitre.oval:tst:20934"/>
            <criterion comment="the version of T2embed.dll is less than 5.0.2195.7348" test_ref="oval:org.mitre.oval:tst:20771"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.3634 or T2embed.dll &lt; 5.1.2600.3634">
            <criterion comment="the version of Fontsub.dll is less than 5.1.2600.3634" test_ref="oval:org.mitre.oval:tst:20493"/>
            <criterion comment="the version of T2embed.dll is less than 5.1.2600.3634" test_ref="oval:org.mitre.oval:tst:20574"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.5888 or T2embed.dll &lt; 5.1.2600.5888">
            <criterion comment="the version of Fontsub.dll is less than 5.1.2600.5888" test_ref="oval:org.mitre.oval:tst:20330"/>
            <criterion comment="the version of T2embed.dll is less than 5.1.2600.5888" test_ref="oval:org.mitre.oval:tst:20465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.2.3790.4603 or T2embed.dll &lt; 5.2.3790.4603">
            <criterion comment="the version of Fontsub.dll is less than 5.2.3790.4603" test_ref="oval:org.mitre.oval:tst:20803"/>
            <criterion comment="the version of T2embed.dll is less than 5.2.3790.4603" test_ref="oval:org.mitre.oval:tst:20441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6000.16939 or T2embed.dll &lt;6.0.6000.16939">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.16939" test_ref="oval:org.mitre.oval:tst:20960"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6000.16939" test_ref="oval:org.mitre.oval:tst:20880"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6000.16000 or T2embed.dll >= 6.0.6000.16000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10227"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9969"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6000.21142 or T2embed.dll &lt;6.0.6000.21142">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.21142" test_ref="oval:org.mitre.oval:tst:20834"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6000.21142" test_ref="oval:org.mitre.oval:tst:20901"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6000.20000 or T2embed.dll >= 6.0.6000.20000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10116"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10120"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6001.18344 or T2embed.dll &lt;6.0.6001.18344">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.18344" test_ref="oval:org.mitre.oval:tst:20514"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.18344" test_ref="oval:org.mitre.oval:tst:20947"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6001.18000 or T2embed.dll >= 6.0.6001.18000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10215"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6001.22544 or T2embed.dll &lt;6.0.6001.22544">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.22544" test_ref="oval:org.mitre.oval:tst:20693"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.22544" test_ref="oval:org.mitre.oval:tst:20548"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6001.22000 or T2embed.dll >= 6.0.6001.22000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9819"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6002.18124 or T2embed.dll &lt;6.0.6002.18124">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.18124" test_ref="oval:org.mitre.oval:tst:20931"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.18124" test_ref="oval:org.mitre.oval:tst:20968"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6002.18000 or T2embed.dll >= 6.0.6002.18000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20873"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20791"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6002.22247 or T2embed.dll &lt;6.0.6002.22247">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.22247" test_ref="oval:org.mitre.oval:tst:20307"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.22247" test_ref="oval:org.mitre.oval:tst:20076"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6002.22000 or T2embed.dll >= 6.0.6002.22000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10029"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is less than 6.1.7600.16444" test_ref="oval:org.mitre.oval:tst:20573"/>
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.16444" test_ref="oval:org.mitre.oval:tst:20972"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20730"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20874"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is less than 6.1.7600.20553" test_ref="oval:org.mitre.oval:tst:20953"/>
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.20553" test_ref="oval:org.mitre.oval:tst:20599"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20857"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20099"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8314" version="3" class="vulnerability">
      <metadata>
        <title>SMB Null Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0022"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:55.645-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:19.120-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:09.453-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.181-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.181-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:12.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8302" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0490)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0490" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0490"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:24.602-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:46.225-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:28.200-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:50.754-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:02.260-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.837-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:11.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:05.018-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:26.293-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8302 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:33.278-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:34.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8298" version="6" class="vulnerability">
      <metadata>
        <title>SMB Client Race Condition Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0017"/>
        <description>Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:59.309-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:17.371-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:07.879-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:49.837-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:49.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:11.161-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:14.307-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4401 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-03T04:01:25.907-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9035"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.16971" test_ref="oval:org.mitre.oval:tst:20528"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.21173" test_ref="oval:org.mitre.oval:tst:20673"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9505"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18375" test_ref="oval:org.mitre.oval:tst:20973"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22575" test_ref="oval:org.mitre.oval:tst:21096"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20899"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18158" test_ref="oval:org.mitre.oval:tst:20724"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20464"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22281" test_ref="oval:org.mitre.oval:tst:21061"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16499" test_ref="oval:org.mitre.oval:tst:21051"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20612" test_ref="oval:org.mitre.oval:tst:20955"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8267" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0248)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0248"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:42.498-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:28:00.020-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:07.637-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:13.167-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.246-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:44.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:51.808-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:01.011-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:55.634-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:55.634-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:09.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:04.076-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:25.552-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8267 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:29.620-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:33.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8186" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0244)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0244"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:40.415-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:27:00.242-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:06.196-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:11.792-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:04.760-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:43.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:43.866-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:59.772-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.306-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.306-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:08.761-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:07.178-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:25.188-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8186 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:28.907-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:32.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8064" version="3" class="vulnerability">
      <metadata>
        <title>DirectShow Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0250"/>
        <description>Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:11.294-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:14.814-05:00">INTERIM</status_change>
            <modified comment="Switched the version tests for Quartz.dll on Windows 2000; with DirectX 9.0x should be 6.5.1.913, without DirectX 9.0x should be 6.1.9.738" date="2010-03-12T14:20:00.051-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:11.304-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.634-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.634-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:07.764-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / AVI filter">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Avifil32.dll is less than 5.0.2195.7359" test_ref="oval:org.mitre.oval:tst:21095"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / Quartz">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.738" test_ref="oval:org.mitre.oval:tst:21059"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / Quartz in DirectX 9.0">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.913" test_ref="oval:org.mitre.oval:tst:20854"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2 / AVI filter">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.3649" test_ref="oval:org.mitre.oval:tst:20939"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2 / Quartz">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3649" test_ref="oval:org.mitre.oval:tst:21048"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3 / AVI filter">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.5908" test_ref="oval:org.mitre.oval:tst:20757"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3 / Quartz">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5908" test_ref="oval:org.mitre.oval:tst:20736"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2 / AVI filter">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 5.2.3790.4625" test_ref="oval:org.mitre.oval:tst:21066"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2 / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4625" test_ref="oval:org.mitre.oval:tst:21092"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6000.16986" test_ref="oval:org.mitre.oval:tst:20777"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6000.16000" test_ref="oval:org.mitre.oval:tst:20862"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6000.21188" test_ref="oval:org.mitre.oval:tst:21082"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6000.20000" test_ref="oval:org.mitre.oval:tst:21068"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.18389" test_ref="oval:org.mitre.oval:tst:20105"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.18000" test_ref="oval:org.mitre.oval:tst:21070"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.22590" test_ref="oval:org.mitre.oval:tst:20946"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.22000" test_ref="oval:org.mitre.oval:tst:20940"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6002.18158" test_ref="oval:org.mitre.oval:tst:20526"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6002.18000" test_ref="oval:org.mitre.oval:tst:20145"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6002.22295" test_ref="oval:org.mitre.oval:tst:20952"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6002.22000" test_ref="oval:org.mitre.oval:tst:20775"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.7600.16490" test_ref="oval:org.mitre.oval:tst:20879"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.6.7600.16000" test_ref="oval:org.mitre.oval:tst:20619"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.7600.20600" test_ref="oval:org.mitre.oval:tst:20804"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.6.7600.20000" test_ref="oval:org.mitre.oval:tst:20613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8006" version="7" class="vulnerability">
      <metadata>
        <title>Hyper-V Instruction Set Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0026"/>
        <description>The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:30.246-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:14.066-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:05.928-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8006 - Updated the OVAL definitions to check if Hyper-V role is enabled.  Also, I've combined the GDR and LDR criteria for the last definition." date="2011-07-26T13:32:00.032-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-07-26T13:33:40.884-04:00">INTERIM</status_change>
            <status_change date="2011-08-15T04:00:12.156-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.556-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.556-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:07.251-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:14.839-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:24.960-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Hyper-V role is enabled" test_ref="oval:org.mitre.oval:tst:43509"/>
        <criteria operator="OR" comment="Affected Software">
          <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 x64">
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <criteria operator="OR" comment="GDR or LDR Service branch">
              <criterion comment="Vid.sys version is less than 6.0.6001.18372" test_ref="oval:org.mitre.oval:tst:20353"/>
              <criteria operator="AND" comment="LDR">
                <criterion comment="Vid.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:20991"/>
                <criterion comment="Vid.sys version is less than 6.0.6001.22572" test_ref="oval:org.mitre.oval:tst:20667"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 SP2 x64">
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <criteria operator="OR" comment="GDR or LDR Service branch">
              <criterion comment="Vid.sys version is less than 6.0.6002.18156" test_ref="oval:org.mitre.oval:tst:20729"/>
              <criteria operator="AND" comment="LDR">
                <criterion comment="Vid.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21100"/>
                <criterion comment="Vid.sys version is less than 6.0.6002.22278" test_ref="oval:org.mitre.oval:tst:20921"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 x64, Windows Server 2008 R2 x64">
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <criteria operator="OR" comment="GDR or LDR Service branch">
              <criterion comment="Vid.sys version is less than 6.1.7600.16475" test_ref="oval:org.mitre.oval:tst:20814"/>
              <criteria operator="AND" comment="LDR">
                <criterion comment="Vid.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:21024"/>
                <criterion comment="Vid.sys version is less than 6.1.7600.20587" test_ref="oval:org.mitre.oval:tst:21040"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7751" version="3" class="vulnerability">
      <metadata>
        <title>SMB NTLM Authentication Lack of Entropy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0231"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:56.561-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:12.404-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:05.057-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:06.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7722" version="10" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability (CVE-2010-0492)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0492"/>
        <description>Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:26.174-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:42.516-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:26.679-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:50.106-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:59.007-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.228-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.228-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:05.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7722 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:32.675-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:31.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7715" version="10" class="vulnerability">
      <metadata>
        <title>XSS Filter Script Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4074"/>
        <description>The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:38.969-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:01:05.623-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:11.481-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:04.456-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:41.397-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:52.945-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:58.244-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.384-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.384-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:04.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7715 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:33.625-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:31.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7637" version="12" class="vulnerability">
      <metadata>
        <title>HTML Sanitization Vulnerability (CVE-2010-3243)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Office SharePoint Server 2007</product>
          <product>Microsoft Windows SharePoint Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3243" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3243"/>
        <description>Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:20.402-04:00">DRAFT</status_change>
            <modified comment="Aggregated Def:7637 and Def:7275 due to common CVE." date="2010-11-03T13:43:00.613-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:15.454-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:18.019-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.665-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.665-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:03.391-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7637 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:44.373-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:37.964-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:36.206-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:30.306-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7637 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:27.805-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:31.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Windows XP, Server 2003">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Windows 7, Server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2007">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="the version of Osafehtm.dll is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11537"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criteria operator="OR" comment="Windows Server 2003 32-bit or Windows Server 2003 64-bit">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6545.5002" test_ref="oval:org.mitre.oval:tst:11364"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7514" version="10" class="vulnerability">
      <metadata>
        <title>Win32k Keyboard Layout Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2743"/>
        <description>The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability."  NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:41.987-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:21.593-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:29.904-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7514 - Replaced duplicate extended definition def:6216 (Windows server 2008 x64 Edition SP2 is installed) with def:5594 (Vista x64 SP2 is installed)" date="2011-07-14T12:58:00.638-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-07-14T13:02:18.465-04:00">INTERIM</status_change>
            <status_change date="2011-08-01T04:00:58.945-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.900-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.900-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:01.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:01.166-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:23.511-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.6033" test_ref="oval:org.mitre.oval:tst:11527"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4769" test_ref="oval:org.mitre.oval:tst:11544"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR" comment="Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18523" test_ref="oval:org.mitre.oval:tst:11810"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22754" test_ref="oval:org.mitre.oval:tst:11488"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18305" test_ref="oval:org.mitre.oval:tst:11583"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22478" test_ref="oval:org.mitre.oval:tst:11508"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16667" test_ref="oval:org.mitre.oval:tst:11343"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20792" test_ref="oval:org.mitre.oval:tst:11609"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7492" version="8" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Microsoft Internet Explorer 8 Developer Tools Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0811" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0811"/>
        <description>Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:54.627-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:57.286-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:48.737-04:00">ACCEPTED</status_change>
            <modified comment="I found when installing KB2508272 (Def:12534) update, the KB2508272 update also includes the update KB980195 (Def:7492). I've added the criteria from def:7492 to def:12534." date="2011-05-23T15:02:39.881-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-05-23T15:02:39.881-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12235 - registry key was pointing to invalid CLSID" date="2011-07-14T10:16:00.951-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:52.228-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8fe85d00-4647-40b9-87e4-5eb8a52f4759}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27459"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8fe85d00-4647-40b9-87e4-5eb8a52f4759}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27590"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7482" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-3329)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3329" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3329"/>
        <description>mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:23.256-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:20.713-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:28.986-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:55.728-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:55.728-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:00.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:03.695-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:23.231-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7482 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:29.997-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:29.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7417" version="9" class="vulnerability">
      <metadata>
        <title>Anchor Element Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3327" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3327"/>
        <description>The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted information by visiting a web page, aka "Anchor Element Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:21.654-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:19.747-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:28.111-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.212-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.212-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:59.572-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:10.241-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:22.837-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7417 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:31.326-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:28.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7410" version="9" class="vulnerability">
      <metadata>
        <title>CSS Special Character Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3325" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3325"/>
        <description>Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a crafted web site, aka "CSS Special Character Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:19.271-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:18.769-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:27.148-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:58.652-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.029-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:22.546-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7410 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:32.943-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:27.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7406" version="11" class="vulnerability">
      <metadata>
        <title>Memory Corruption Vulnerability (CVE-2010-1262)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1262"/>
        <description>Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:19.562-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:49.906-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:45.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:13.824-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:57.305-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.290-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.290-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:57.658-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:12.822-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:22.250-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7406 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:31.978-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:27.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1649" test_ref="oval:org.mitre.oval:tst:27761"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3698" test_ref="oval:org.mitre.oval:tst:27446"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5969" test_ref="oval:org.mitre.oval:tst:27626"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4696" test_ref="oval:org.mitre.oval:tst:27176"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7358" version="5" class="vulnerability">
      <metadata>
        <title>Print Spooler Service Impersonation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2729" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2729"/>
        <description>The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-09-16T11:38:52.863-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:42.626-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:28.425-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:56.790-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:56.790-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:56.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Spoolsv.exe version is less than 5.1.2600.6024" test_ref="oval:org.mitre.oval:tst:11063"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Spoolsv.exe version is less than 5.2.3790.4759" test_ref="oval:org.mitre.oval:tst:10999"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Spoolsv.exe version is less than 6.0.6001.18511" test_ref="oval:org.mitre.oval:tst:11637"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spoolsv.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11237"/>
              <criterion comment="Spoolsv.exe version is less than 6.0.6001.22743" test_ref="oval:org.mitre.oval:tst:11293"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Spoolsv.exe version is less than 6.0.6002.18294" test_ref="oval:org.mitre.oval:tst:11534"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spoolsv.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11602"/>
              <criterion comment="Spoolsv.exe version is less than 6.0.6002.22468" test_ref="oval:org.mitre.oval:tst:11035"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Spoolsv.exe version is less than 6.1.7600.16661" test_ref="oval:org.mitre.oval:tst:11090"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spoolsv.exe version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11311"/>
              <criterion comment="Spoolsv.exe version is less than 6.1.7600.20785" test_ref="oval:org.mitre.oval:tst:11301"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7324" version="11" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-1259)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1259" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1259"/>
        <description>Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:12.647-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:44.204-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:40.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:07.127-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:56.029-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.790-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.790-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:54.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:11.667-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:21.878-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7324 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:30.366-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:26.869-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1649" test_ref="oval:org.mitre.oval:tst:27761"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3698" test_ref="oval:org.mitre.oval:tst:27446"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5969" test_ref="oval:org.mitre.oval:tst:27626"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4696" test_ref="oval:org.mitre.oval:tst:27176"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7283" version="9" class="vulnerability">
      <metadata>
        <title>Win32k TrueType Font Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1255"/>
        <description>The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:25.000-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:36.500-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:37.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7283 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T15:59:00.878-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T16:00:06.146-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:13.412-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:50.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:57.050-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:21.536-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7397" test_ref="oval:org.mitre.oval:tst:27601"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3706" test_ref="oval:org.mitre.oval:tst:27275"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5976" test_ref="oval:org.mitre.oval:tst:27640"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4702" test_ref="oval:org.mitre.oval:tst:27693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18468" test_ref="oval:org.mitre.oval:tst:27353"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22682" test_ref="oval:org.mitre.oval:tst:27380"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18253" test_ref="oval:org.mitre.oval:tst:27138"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22396" test_ref="oval:org.mitre.oval:tst:27022"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16585" test_ref="oval:org.mitre.oval:tst:27474"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20704" test_ref="oval:org.mitre.oval:tst:27593"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7272" version="7" class="vulnerability">
      <metadata>
        <title>Comctl32 Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2746" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2746"/>
        <description>Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:55.409-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:15.250-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:23.979-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7272 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:41.354-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:46.442-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:49.654-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows XP SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="The version of Comctl32.dll is less than 5.82.2900.6028" test_ref="oval:org.mitre.oval:tst:11533"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 sp2, Server 2003 x86/x64/ia64 sp2">
          <criteria operator="OR" comment="Microsoft Windows XP x64 Edition SP2, Server 2003 SP2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="The version of Comctl32.dll is less than 5.82.3790.4770" test_ref="oval:org.mitre.oval:tst:11557"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 sp1, Windows Server 2008 x86/x64, Windows Server 2008 ia64">
          <criteria operator="OR" comment="Microsoft Windows Vista SP1 x64/32-bit, Server 2008 32-bit/64-bit/ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.6001.18523" test_ref="oval:org.mitre.oval:tst:11561"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.6001.22000" test_ref="oval:org.mitre.oval:tst:11519"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.6001.22755" test_ref="oval:org.mitre.oval:tst:11516"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 sp2, Windows Server 2008 x86/x64 sp2, Windindows Server 2008 ia64 sp2">
          <criteria operator="OR" comment="Microsoft Windows Vista SP2 32-bit/x64, Server 2008 SP2 32-bit/x64/Itanium">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.6002.18305" test_ref="oval:org.mitre.oval:tst:11513"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.6002.22000" test_ref="oval:org.mitre.oval:tst:11503"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.6002.22480" test_ref="oval:org.mitre.oval:tst:11494"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows 7 x86/x64, Windows 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows 7 32-bit/x64, Server 2008 R2 x64/Itanium">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.7600.16661" test_ref="oval:org.mitre.oval:tst:11441"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.7600.20000" test_ref="oval:org.mitre.oval:tst:11432"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.7600.20787" test_ref="oval:org.mitre.oval:tst:11728"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7195" version="7" class="vulnerability">
      <metadata>
        <title>Remote code execution vulnerability in Canonical Display Driver</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3678"/>
        <description>Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-19T11:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-05-19T15:51:02.110-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:33.356-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:13.297-04:00">ACCEPTED</status_change>
            <modified comment="Added new file tests in the def:7195 to check for cdd.dll version" date="2010-07-14T17:39:00.479-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-07-14T17:43:02.526-04:00">INTERIM</status_change>
            <status_change date="2010-08-02T04:00:09.795-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.572-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.572-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:49.240-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="GDR or LDR update has been applied">
          <criterion comment="Cdd.dll version is less than 6.1.7600.16595" test_ref="oval:org.mitre.oval:tst:40738"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Cdd.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:40644"/>
            <criterion comment="Cdd.dll version is less than 6.1.7600.20715" test_ref="oval:org.mitre.oval:tst:40259"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7186" version="5" class="vulnerability">
      <metadata>
        <title>SMB Client Incomplete Response Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3676"/>
        <description>The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:03.269-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:46.998-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:33.004-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.478-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.478-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:48.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7176" version="5" class="vulnerability">
      <metadata>
        <title>Windows Kernel Malformed Image Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0482" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0482"/>
        <description>The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:30.424-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:46.708-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:32.698-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.290-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.290-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:48.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11261"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7164" version="5" class="vulnerability">
      <metadata>
        <title>SMB Client Transaction Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0270"/>
        <description>The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:03.485-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:45.349-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:31.305-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.275-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.275-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:46.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7158" version="11" class="vulnerability">
      <metadata>
        <title>XML Signature HMAC Truncation Authentication Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217"/>
        <description>The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:33:22.713-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:28.102-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:29.682-04:00">ACCEPTED</status_change>
            <modified comment="Removed the Windows Server 2003 SP2 (x86) extended def reference in the larger .Net Framework 1.1 criteria section.  The proper test for .Net Framework 1.1 on 2003 x86 was already broken out separately." date="2010-07-28T13:32:00.593-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-07-28T13:33:31.800-04:00">INTERIM</status_change>
            <status_change date="2010-08-16T04:10:49.309-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.243-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.243-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:46.216-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7158 - Submitting updated MS10-041 bulletin. def:7158 - updated to include LDR support." date="2013-05-29T15:56:00.291-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-05-29T15:59:21.130-04:00">INTERIM</status_change>
            <status_change date="2013-06-17T04:00:30.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7158 - extended definitions of OS are without SP checks" date="2014-07-28T17:44:00.322-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:46:27.851-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:24.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 1.1 SP1">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of Mscorlib.dll is less than 1.1.4322.2463" test_ref="oval:org.mitre.oval:tst:27588"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 1.1 Service Pack 1">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of System.Security.dll is less than 1.1.4322.2460" test_ref="oval:org.mitre.oval:tst:27732"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="System.web.dll version is less than 2.0.50727.1878" test_ref="oval:org.mitre.oval:tst:27523"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP2 or 3.5 SP1">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for Microsoft .NET Framework 2.0 Service Pack 2 or 3.5 SP1">
            <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
            <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          </criteria>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of System.Security.dll is less than 2.0.50727.3613" test_ref="oval:org.mitre.oval:tst:27623"/>
            <criteria operator="AND" comment="Check for LDR version">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:81021"/>
              <criterion comment="Check if System.Security.dll version is less than 2.0.50727.4434" test_ref="oval:org.mitre.oval:tst:81257"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="the version of System.Security.dll is less than 2.0.50727.1879" test_ref="oval:org.mitre.oval:tst:27098"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5 SP1 on Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of system.security.dll is less than 2.0.50727.4204" test_ref="oval:org.mitre.oval:tst:27451"/>
            <criteria operator="AND" comment="Check for LDR versions">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.4300" test_ref="oval:org.mitre.oval:tst:80770"/>
              <criterion comment="Check if System.Security.dll version is less than 2.0.50727.4434" test_ref="oval:org.mitre.oval:tst:81257"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft .NET Framework 3.5.1 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of system.security.dll is less than 2.0.50727.4951" test_ref="oval:org.mitre.oval:tst:27053"/>
            <criteria operator="AND" comment="Check for LDR versions">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:org.mitre.oval:tst:80869"/>
              <criterion comment="Check if system.security.dll version is less than 2.0.50727.5007" test_ref="oval:org.mitre.oval:tst:81083"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7149" version="11" class="vulnerability">
      <metadata>
        <title>IIS Authentication Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Information Server (IIS) 6.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1256"/>
        <description>Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:33:07.175-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:26.319-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:28.534-04:00">ACCEPTED</status_change>
            <modified comment="Updated the tests to account for EPA installation.  The file in the original tests, 'w3dt.dll', was not updated by MS10-040 on all platforms." date="2010-08-03T11:07:00.009-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-03T11:08:14.118-04:00">INTERIM</status_change>
            <status_change date="2010-08-23T04:00:34.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7149 - Modified to reflect MS10-040 better." date="2011-07-07T12:56:00.741-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-07-07T12:59:12.859-04:00">INTERIM</status_change>
            <status_change date="2011-07-25T04:00:10.676-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.119-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.119-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:45.331-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7149 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:14.536-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:32.258-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Windows Server 2003 x86/x64/ia64 SP2 - IIS 6.0">
          <criteria operator="OR" comment="Operating System Check for 2003 SP2 (x86, x64, ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="The version of W3dt.dll is less than 6.0.3790.4693" test_ref="oval:org.mitre.oval:tst:27546"/>
          <criterion comment="The version of W3dt.dll is greater than or equal to 6.0.3790.4667" test_ref="oval:org.mitre.oval:tst:40816"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1 - IIS 7.0 - GDR">
          <criteria operator="OR" comment="Operating System Check for Vista SP1 and server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Check">
            <criterion comment="The version of Iisw3adm.dll is less than 7.0.6001.18428" test_ref="oval:org.mitre.oval:tst:40772"/>
            <criteria operator="AND" comment="LDR Check">
              <criterion comment="The version of Iisw3adm.dll is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:40468"/>
              <criterion comment="The version of Iisw3adm.dll is less than 7.0.6001.22675" test_ref="oval:org.mitre.oval:tst:41210"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2 - IIS 7.0 - GDR">
          <criteria operator="OR" comment="Operating System Check for Vista SP2 and Server 2008 SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Check">
            <criterion comment="The version of Iisw3adm.dll is less than 7.0.6002.18247" test_ref="oval:org.mitre.oval:tst:40216"/>
            <criteria operator="AND" comment="LDR Check">
              <criterion comment="The version of Iisw3adm.dll is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:40586"/>
              <criterion comment="The version of Iisw3adm.dll is less than 7.0.6002.22388" test_ref="oval:org.mitre.oval:tst:40780"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - IIS 7.5 - GDR">
          <criteria operator="OR" comment="Operating System Check for Windows 7 and Server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.5 is installed" definition_ref="oval:org.mitre.oval:def:6856"/>
          <criteria operator="OR" comment="GDR or LDR Check">
            <criterion comment="The version of Authsspi.dll is less than 7.5.7600.16576" test_ref="oval:org.mitre.oval:tst:27697"/>
            <criteria operator="AND" comment="LDR Check">
              <criterion comment="The version of Authsspi.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:27756"/>
              <criterion comment="The version of Authsspi.dll is less than 7.5.7600.20694" test_ref="oval:org.mitre.oval:tst:27782"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7145" version="11" class="vulnerability">
      <metadata>
        <title>Cross-Domain Information Disclosure Vulnerability (CVE-2010-0255)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0255"/>
        <description>Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:13.531-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:25.186-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:27.675-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:10.846-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:54.507-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:44.427-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.193-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:20.857-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7145 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:54.331-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:24.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7129" version="8" class="vulnerability">
      <metadata>
        <title>SMB Client Memory Allocation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0269"/>
        <description>The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:12.648-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:43.173-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:29.207-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:44.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:44.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:43.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:15.061-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4401 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-03T04:01:20.523-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Mrxsmb.sys version is less than 5.0.2195.7379" test_ref="oval:org.mitre.oval:tst:11414"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.3675" test_ref="oval:org.mitre.oval:tst:11126"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.5944" test_ref="oval:org.mitre.oval:tst:11710"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4671" test_ref="oval:org.mitre.oval:tst:11515"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9035"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.17025" test_ref="oval:org.mitre.oval:tst:11088"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.21230" test_ref="oval:org.mitre.oval:tst:11469"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9505"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18431" test_ref="oval:org.mitre.oval:tst:11662"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22641" test_ref="oval:org.mitre.oval:tst:11205"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20899"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18213" test_ref="oval:org.mitre.oval:tst:10963"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20464"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22346" test_ref="oval:org.mitre.oval:tst:11499"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7127" version="8" class="vulnerability">
      <metadata>
        <title>IIS Repeated Parameter Request Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Information Server (IIS) 5.1</product>
          <product>Microsoft Internet Information Server (IIS) 6.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1899" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1899"/>
        <description>Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-09-16T11:39:34.446-04:00">DRAFT</status_change>
            <modified comment="Added new check for asp.dll on IIS 5.1/Win XP SP3 and corrected object obj:4885 to identify asp51.dll under system32\dllcache directory." date="2010-09-22T21:20:00.563-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-10-11T04:00:11.366-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:07.355-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:45.821-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.821-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:42.466-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7127 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:14.727-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable IIS 5.1 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criteria operator="OR" comment="file version">
            <criterion comment="the version of asp51.dll is less than 5.1.2600.6007" test_ref="oval:org.mitre.oval:tst:11663"/>
            <criterion comment="the version of asp.dll is less than 5.1.2600.6007" test_ref="oval:org.mitre.oval:tst:11082"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 6.0 on Windows XP x64, Windows Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="The version of asp.dll is less than 6.0.3790.4735" test_ref="oval:org.mitre.oval:tst:11245"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 7.0 on Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of asp.dll is less than 7.0.6001.18497" test_ref="oval:org.mitre.oval:tst:11366"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of asp.dll is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11214"/>
              <criterion comment="The version of asp.dll is less than 7.0.6001.22718" test_ref="oval:org.mitre.oval:tst:11379"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 7.0 on Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of asp.dll is less than 7.0.6002.18276" test_ref="oval:org.mitre.oval:tst:11539"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of asp.dll is greater than or equal 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11514"/>
              <criterion comment="The version of asp.dll is less than 7.0.6002.22431" test_ref="oval:org.mitre.oval:tst:11664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 7.5 on Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.5 is installed" definition_ref="oval:org.mitre.oval:def:6856"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of asp.dll is less than 7.5.7600.16620" test_ref="oval:org.mitre.oval:tst:11219"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of asp.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:11656"/>
              <criterion comment="The version of asp.dll is less than 7.5.7600.20741" test_ref="oval:org.mitre.oval:tst:11498"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:460" version="4" class="inventory">
      <metadata>
        <title>Microsoft IIS 5.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft IIS 5.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:5.1"/>
        <description>The application Microsoft IIS 5.1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:27.089-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.067-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.815-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:14:32.837-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:46.398-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:460 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.071-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS 5.1 Minor Version" test_ref="oval:org.mitre.oval:tst:1357"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:227" version="4" class="inventory">
      <metadata>
        <title>Microsoft IIS 6.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft IIS 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:6.0"/>
        <description>The application Microsoft IIS 6.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:16.652-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.614-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.336-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:13:22.361-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:39.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:227 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.941-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:14.871-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 6" test_ref="oval:org.mitre.oval:tst:170"/>
        <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7124" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-1261)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1261"/>
        <description>The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:18.985-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:23.322-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:26.457-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:12.401-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:53.783-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:45.525-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.525-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:41.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7124 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.328-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7120" version="17" class="vulnerability">
      <metadata>
        <title>LSASS Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0820" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0820"/>
        <description>Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) in Windows Vista SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote authenticated users to execute arbitrary code via malformed LDAP messages, aka "LSASS Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-09-16T11:39:59.519-04:00">DRAFT</status_change>
            <modified comment="Replaced the tst:10696 with tst:10634 to check also for Member Servers." date="2010-09-17T14:57:00.688-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-10-04T04:00:39.679-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:23.034-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7120 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:40:49.403-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15869 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:22.853-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15869 - Fixed false positive when checking NTDS registry key.  Replaced withe object that checks ImagePath name." date="2011-07-08T16:56:00.948-04:00">
              <contributor organization="Hewlett-Packard">R, Yamini Mohan</contributor>
            </modified>
            <status_change date="2011-07-08T16:57:05.997-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:5285 - obj:5285 is pointing to windows\system32 directory. But, adamdsa.dll file by default will be in windows\ADAM directory" date="2011-07-14T10:24:00.833-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15869 - corrected to use a valid key &amp; nil name" date="2011-07-14T10:26:00.623-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-08-01T04:00:57.368-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:40.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7120 - modified vulnerabilities which check the version of file adamdsa.dll" date="2013-12-18T16:36:00.218-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-18T16:44:39.818-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:48.493-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:89195 - bulletin MS14-016, for the month of Mar 2014." date="2014-03-18T14:40:00.553-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-03-18T14:42:03.969-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:56.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows XP (x86) SP3, Windows XP (x64) SP2, Windows Server 2003 x64/x86/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.4722" test_ref="oval:org.mitre.oval:tst:11125"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 x64/x86/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR" comment="Active Directory or ADAM">
            <criteria operator="AND">
              <criterion comment="the system is being used as: Member Server, BDC or PDC (DomainRole is 3, 4 or 5)" test_ref="oval:org.mitre.oval:tst:10634"/>
              <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
              <criterion comment="ntdsa.dll version is less than 5.2.3790.4754" test_ref="oval:org.mitre.oval:tst:11434"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
              <criterion comment="adamdsa.dll version is less than 1.1.3790.4722" test_ref="oval:org.mitre.oval:tst:11125"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="ntdsai.dll version is less than 6.0.6001.18461" test_ref="oval:org.mitre.oval:tst:10991"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="ntdsai.dll version is less than 6.0.6001.22672" test_ref="oval:org.mitre.oval:tst:11431"/>
              <criterion comment="ntdsai.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10907"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="ntdsai.dll version is less than 6.0.6002.18244" test_ref="oval:org.mitre.oval:tst:11192"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="ntdsai.dll version is less than 6.0.6002.22384" test_ref="oval:org.mitre.oval:tst:11413"/>
              <criterion comment="ntdsai.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10980"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="ntdsai.dll version is less than 6.1.7600.16612" test_ref="oval:org.mitre.oval:tst:11808"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="ntdsai.dll version is less than 6.1.7600.20735" test_ref="oval:org.mitre.oval:tst:11314"/>
              <criterion comment="ntdsai.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11632"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7072" version="5" class="vulnerability">
      <metadata>
        <title>OpenType CFF Font Driver Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0819"/>
        <description>Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:45.172-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:19.758-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:24.036-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.165-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.165-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:40.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Atmfd.dll is less than 5.0.2.227" test_ref="oval:org.mitre.oval:tst:27043"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2/SP3">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.2.2.228" test_ref="oval:org.mitre.oval:tst:26783"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7067" version="11" class="vulnerability">
      <metadata>
        <title>SMTP Server MX Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>SMTP</product>
          <product>Microsoft Exchange Server 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0024"/>
        <description>The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:57.808-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:40.554-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:26.034-04:00">ACCEPTED</status_change>
            <modified comment="Updated definition and related items because Microsoft has re-released the bulletin MS10-024 to reoffer the updates for Windows Server 2008 and Windows Server 2008 R2." date="2010-11-10T17:30:00.607-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-11-10T18:08:07.712-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:20.982-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:39.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:59.067-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:20.280-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7067 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:57.894-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="The version of smtpsvc.dll is less than 5.0.2195.7381" test_ref="oval:org.mitre.oval:tst:11642"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.2600.3680" test_ref="oval:org.mitre.oval:tst:11743"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.2600.5949" test_ref="oval:org.mitre.oval:tst:11572"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.3790.4675" test_ref="oval:org.mitre.oval:tst:11143"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2008 32bit/x64">
          <criteria operator="OR" comment="Microsoft Server 2008 32bit/x64">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of smtpsvc.dll is less than 7.0.6001.18485" test_ref="oval:org.mitre.oval:tst:11603"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of smtpsvc.dll is greater than or equal 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11323"/>
              <criterion comment="The version of smtpsvc.dll is less than 7.0.6001.22704" test_ref="oval:org.mitre.oval:tst:11171"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 32bit/x64">
          <criteria operator="OR" comment="Microsoft Server 2008 32bit/x64">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of smtpsvc.dll is less than 7.0.6002.18264" test_ref="oval:org.mitre.oval:tst:11520"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of smtpsvc.dll is greater than or equal 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11373"/>
              <criterion comment="The version of smtpsvc.dll is less than 7.0.6002.22417" test_ref="oval:org.mitre.oval:tst:11328"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 R2 x86/x64/ia64">
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of smtpsvc.dll is less than 7.5.7600.16601" test_ref="oval:org.mitre.oval:tst:11754"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of smtpsvc.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:11889"/>
              <criterion comment="The version of smtpsvc.dll is less than 7.5.7600.20723" test_ref="oval:org.mitre.oval:tst:11532"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Exchange Server 2003 SP2">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:1869"/>
          <criterion comment="The version of Msgfilter.dll is less than 6.5.7656.2" test_ref="oval:org.mitre.oval:tst:11056"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1869" version="6" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2003 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <description>Exchange Server 2003 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:36.384-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:36.442-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.345-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:48:05.799-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:03.015-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1869 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:51.723-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:35.205-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:58.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Exchange Server 2003,SP2 is installed." test_ref="oval:org.mitre.oval:tst:1202"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7059" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-3328)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3328" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3328"/>
        <description>Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:22.389-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:11.414-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:20.058-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.978-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.978-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:38.409-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:11.435-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:20.025-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7059 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:52.726-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.032-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6956" version="11" class="vulnerability">
      <metadata>
        <title>MHTML Mime-Formatted Request Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-0096" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0096"/>
        <description>The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-01-31T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-01-31T17:59:59.792-05:00">DRAFT</status_change>
            <status_change date="2011-02-21T04:01:12.881-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:02.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6956 - New Definitions for April 2011 Patch Tuesday" date="2011-04-18T00:15:00.288-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-18T00:16:04.297-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:41.506-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.415-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.415-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:37.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12418 - Patch Tuesday - 7/2012 - also added comment to state." date="2012-07-13T11:28:00.032-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-07-13T11:34:02.798-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:35.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.6090" test_ref="oval:org.mitre.oval:tst:41714"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows XP SP2 x64, Server 2003 SP2 x86/x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows XP SP2 x64, Server 2003 SP2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.3790.4841" test_ref="oval:org.mitre.oval:tst:42540"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18612" test_ref="oval:org.mitre.oval:tst:42392"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22867" test_ref="oval:org.mitre.oval:tst:42501"/>
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="Microsoft Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18417" test_ref="oval:org.mitre.oval:tst:42538"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
              <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22601" test_ref="oval:org.mitre.oval:tst:42194"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.16776" test_ref="oval:org.mitre.oval:tst:42627"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11895"/>
              <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.20918" test_ref="oval:org.mitre.oval:tst:42493"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64 SP1, Windows Server 2008 R2 x64 SP1">
          <criteria operator="OR" comment="Vulnerable Microsoft Windows 7 x86/x64 SP1, Windows Server 2008 R2 x64 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Inetcomm.dll is less than 6.1.7601.17574" test_ref="oval:org.mitre.oval:tst:42001"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42490"/>
              <criterion comment="the version of Inetcomm.dll is less than 6.1.7601.21677" test_ref="oval:org.mitre.oval:tst:42660"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6948" version="9" class="vulnerability">
      <metadata>
        <title>Win32k Window Creation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0485" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0485"/>
        <description>The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:24.406-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:11.734-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:19.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6948 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T15:59:00.878-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T16:00:04.782-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:12.131-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.994-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.994-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:36.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:00.911-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:19.764-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7397" test_ref="oval:org.mitre.oval:tst:27601"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3706" test_ref="oval:org.mitre.oval:tst:27275"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5976" test_ref="oval:org.mitre.oval:tst:27640"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4702" test_ref="oval:org.mitre.oval:tst:27693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18468" test_ref="oval:org.mitre.oval:tst:27353"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22682" test_ref="oval:org.mitre.oval:tst:27380"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18253" test_ref="oval:org.mitre.oval:tst:27138"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22396" test_ref="oval:org.mitre.oval:tst:27022"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16585" test_ref="oval:org.mitre.oval:tst:27474"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20704" test_ref="oval:org.mitre.oval:tst:27593"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6933" version="7" class="vulnerability">
      <metadata>
        <title>Request Header Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Information Server (IIS) 7.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2730"/>
        <description>Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-09-16T11:39:35.310-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:38.851-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:21.682-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.619-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.619-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:36.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6933 - The attached file contains modified vulnerability def:6933. The new test was added." date="2013-07-11T13:22:00.246-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-11T13:28:18.744-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:46.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Vulnerable OS 7\2008 r2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criterion negate="true" comment="The version of cgi.dll is equal to 7.5.7600.16385" test_ref="oval:org.mitre.oval:tst:81632"/>
        <extend_definition comment="Microsoft IIS 7.5 is installed" definition_ref="oval:org.mitre.oval:def:6856"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="The version of cgi.dll is less than 7.5.7600.16632" test_ref="oval:org.mitre.oval:tst:11599"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="The version of cgi.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:11765"/>
            <criterion comment="The version of cgi.dll is less than 7.5.7600.20752" test_ref="oval:org.mitre.oval:tst:11459"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6928" version="9" class="vulnerability">
      <metadata>
        <title>Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3330" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3330"/>
        <description>Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:23.959-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:09.675-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:18.717-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.181-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.181-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:35.465-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:58.366-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:19.499-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6928 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:56.837-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:22.032-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6918" version="8" class="vulnerability">
      <metadata>
        <title>SMB Client Response Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0476"/>
        <description>The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:13.397-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:32.979-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:18.022-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.915-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.915-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:34.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.918-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4401 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-03T04:01:19.180-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4671" test_ref="oval:org.mitre.oval:tst:11515"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9035"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.17025" test_ref="oval:org.mitre.oval:tst:11088"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.21230" test_ref="oval:org.mitre.oval:tst:11469"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9505"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18431" test_ref="oval:org.mitre.oval:tst:11662"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22641" test_ref="oval:org.mitre.oval:tst:11205"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20899"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18213" test_ref="oval:org.mitre.oval:tst:10963"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20464"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22346" test_ref="oval:org.mitre.oval:tst:11499"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6886" version="10" class="vulnerability">
      <metadata>
        <title>Cabview Corruption Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Cabinet File Viewer Shell Extension</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0487"/>
        <description>The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:58.556-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:30.840-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:15.984-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:33.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.752-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.740-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6886 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:13.740-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:21.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of Cabview.dll is less than 5.0.3900.7369" test_ref="oval:org.mitre.oval:tst:11298"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.2900.3663" test_ref="oval:org.mitre.oval:tst:11381"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.2900.5927" test_ref="oval:org.mitre.oval:tst:11525"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.3790.4649" test_ref="oval:org.mitre.oval:tst:11740"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6000.17002" test_ref="oval:org.mitre.oval:tst:11864"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:11560"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6000.21203" test_ref="oval:org.mitre.oval:tst:11830"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6001.18404" test_ref="oval:org.mitre.oval:tst:11297"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11529"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6001.22605" test_ref="oval:org.mitre.oval:tst:11130"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6002.18184" test_ref="oval:org.mitre.oval:tst:11490"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11204"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6002.22311" test_ref="oval:org.mitre.oval:tst:11308"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.1.7600.16500" test_ref="oval:org.mitre.oval:tst:11424"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11563"/>
          <criterion comment="the version of Cabview.dll is less than 6.1.7600.20613" test_ref="oval:org.mitre.oval:tst:11708"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6881" version="5" class="vulnerability">
      <metadata>
        <title>Embedded OpenType Font Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1883" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1883"/>
        <description>Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:10.784-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:08.415-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:17.401-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.353-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.353-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:32.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of T2embed.dll is less than 5.1.2600.6031" test_ref="oval:org.mitre.oval:tst:11271"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of T2embed.dll is less than 5.2.3790.4766" test_ref="oval:org.mitre.oval:tst:11576"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.18520" test_ref="oval:org.mitre.oval:tst:11376"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of T2embed.dll is less than 6.0.6001.22750" test_ref="oval:org.mitre.oval:tst:11253"/>
              <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10118"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.18301" test_ref="oval:org.mitre.oval:tst:11550"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of T2embed.dll is less than 6.0.6002.22475" test_ref="oval:org.mitre.oval:tst:11549"/>
              <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10002"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.16663" test_ref="oval:org.mitre.oval:tst:11244"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of T2embed.dll is less than 6.1.7600.20788" test_ref="oval:org.mitre.oval:tst:11480"/>
              <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20099"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6859" version="5" class="vulnerability">
      <metadata>
        <title>SMB Client Message Size Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0477" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0477"/>
        <description>The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:13.972-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:29.816-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:14.910-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.462-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.462-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:32.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6835" version="13" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability (CVE-2010-0249)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0249"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-15T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-19T07:03:25.323-05:00">DRAFT</status_change>
            <modified comment="Updated title, all tests and states" date="2010-01-22T11:57:00.675-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:32:00.227-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:03.010-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:07.692-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.899-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:30.203-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:48.963-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:51.963-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:51.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:51.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:30.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:01.102-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.374-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6835 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:54.699-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6832" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-3331)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3331" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3331"/>
        <description>Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:24.861-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:07.005-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:15.955-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:51.650-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:51.650-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:29.800-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:59.907-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.007-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6832 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:53.987-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6824" version="10" class="vulnerability">
      <metadata>
        <title>.NET Framework x64 JIT Compiler Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3228"/>
        <description>The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote attackers to execute arbitrary code via a crafted .NET application that triggers memory corruption, aka ".NET Framework x64 JIT Compiler Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:19.917-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:21:00.547-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:07.663-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:10.998-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7311 - Corrected repeated hive element in the key" date="2010-12-31T10:57:00.761-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-31T10:58:58.150-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:19.852-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.946-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.946-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:29.198-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6824 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:14.227-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="os section">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="clrjit.dll version is less than 4.0.30319.202" test_ref="oval:org.mitre.oval:tst:11601"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="clrjit.dll version is greater than or equal to 4.0.30319.300" test_ref="oval:org.mitre.oval:tst:11649"/>
            <criterion comment="clrjit.dll version is less than 4.0.30319.336" test_ref="oval:org.mitre.oval:tst:11626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6806" version="5" class="vulnerability">
      <metadata>
        <title>TLSv1 Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3229" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3229"/>
        <description>The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:50:31.852-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:06.309-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:15.318-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:54.603-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:54.603-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:28.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.0.6001.18507" test_ref="oval:org.mitre.oval:tst:11456"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:41291"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6001.22739" test_ref="oval:org.mitre.oval:tst:11696"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.0.6002.18290" test_ref="oval:org.mitre.oval:tst:11915"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:41611"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6002.22463" test_ref="oval:org.mitre.oval:tst:11148"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.1.7600.16661" test_ref="oval:org.mitre.oval:tst:11477"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:41670"/>
              <criterion comment="the version of schannel.dll is less than 6.1.7600.20785" test_ref="oval:org.mitre.oval:tst:11405"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6789" version="6" class="vulnerability">
      <metadata>
        <title>Permissions on New Cluster Disks Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3223"/>
        <description>The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:50:38.069-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:39:00.121-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:06.688-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:09.954-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.290-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.290-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:28.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="The version of Clusres.dll is less than 6.1.7600.16652" test_ref="oval:org.mitre.oval:tst:11825"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="The version of Clusres.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11481"/>
            <criterion comment="The version of Clusres.dll is less than 6.1.7600.20777" test_ref="oval:org.mitre.oval:tst:11574"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6787" version="10" class="vulnerability">
      <metadata>
        <title>WinVerifyTrust Signature Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Authenticode Signature Verification</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0486"/>
        <description>The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:56.734-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:25.389-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:10.246-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.384-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.384-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:27.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.423-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:17.736-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6787 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:15.000-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:19.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2195.7375" test_ref="oval:org.mitre.oval:tst:11686"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2600.3661" test_ref="oval:org.mitre.oval:tst:11304"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2600.5922" test_ref="oval:org.mitre.oval:tst:11690"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 5.131.3790.4642" test_ref="oval:org.mitre.oval:tst:11359"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6000.16984" test_ref="oval:org.mitre.oval:tst:11719"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:11349"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6000.21186" test_ref="oval:org.mitre.oval:tst:11492"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6001.18387" test_ref="oval:org.mitre.oval:tst:11262"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11526"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6001.22588" test_ref="oval:org.mitre.oval:tst:11567"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6002.18169" test_ref="oval:org.mitre.oval:tst:11040"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11196"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6002.22293" test_ref="oval:org.mitre.oval:tst:11738"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.1.7600.16493" test_ref="oval:org.mitre.oval:tst:11401"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11722"/>
          <criterion comment="the version of wintrust.dll is less than 6.1.7600.20605" test_ref="oval:org.mitre.oval:tst:11330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6770" version="5" class="vulnerability">
      <metadata>
        <title>Windows Virtual Path Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0481" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0481"/>
        <description>The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:29.838-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:23.884-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:08.530-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:26.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.17021" test_ref="oval:org.mitre.oval:tst:11259"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21226" test_ref="oval:org.mitre.oval:tst:11841"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10821"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18427" test_ref="oval:org.mitre.oval:tst:11737"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22636" test_ref="oval:org.mitre.oval:tst:11674"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10870"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18209" test_ref="oval:org.mitre.oval:tst:11433"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22341" test_ref="oval:org.mitre.oval:tst:11585"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11261"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6734" version="10" class="vulnerability">
      <metadata>
        <title>Outlook Express and Windows Mail Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Outlook Express</product>
          <product>Microsoft Windows Mail</product>
          <product>Microsoft Windows Live Mail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816"/>
        <description>Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-05-12T12:23:25.542-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:28.757-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:05.608-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.244-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.244-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:24.920-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6734 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:29.064-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:08.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6734 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:13.458-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:18.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 5.5 SP2 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 5.5 SP2 is installed." definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of Inetcomm.dll is less than 5.50.5010.200" test_ref="oval:org.mitre.oval:tst:11816"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 SP1 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 6 SP1 is installed." definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2800.2001" test_ref="oval:org.mitre.oval:tst:11216"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.3664" test_ref="oval:org.mitre.oval:tst:11320"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.5931" test_ref="oval:org.mitre.oval:tst:10972"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP (64-bit), Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP (64-bit), Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.3790.4657" test_ref="oval:org.mitre.oval:tst:11267"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18416" test_ref="oval:org.mitre.oval:tst:11337"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22621" test_ref="oval:org.mitre.oval:tst:11718"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18197" test_ref="oval:org.mitre.oval:tst:11803"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22325" test_ref="oval:org.mitre.oval:tst:11524"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail Windows Server 2008 ia64 - GDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18427" test_ref="oval:org.mitre.oval:tst:11799"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - LDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22636" test_ref="oval:org.mitre.oval:tst:11536"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - GDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18209" test_ref="oval:org.mitre.oval:tst:11316"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - LDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22341" test_ref="oval:org.mitre.oval:tst:11688"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.16543" test_ref="oval:org.mitre.oval:tst:11904"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11895"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.20659" test_ref="oval:org.mitre.oval:tst:11232"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:504" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 5.5 SP2 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express 5.5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:5.5:sp2"/>
        <description>Microsoft Outlook Express 5.5 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:59.147-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:41.385-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:03.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Outlook Express 5.5 SP2 is installed" test_ref="oval:org.mitre.oval:tst:1514"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:488" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 6 SP1 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express 6</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:6.00.2800.1106"/>
        <description>Microsoft Outlook Express 6 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:58.863-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:38.525-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:03.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Outlook Express 6 SP1 is installed" test_ref="oval:org.mitre.oval:tst:1355"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:208" version="8" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 6.0 for Windows XP/2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:6.0"/>
        <description>Microsoft Outlook Express 6.0 for Windows XP/2003 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-03T12:32:22">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-07-03T14:04:49.139-04:00">DRAFT</status_change>
            <status_change date="2007-07-18T15:57:53.037-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:15.591-04:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:51.618-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:31.131-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1485 - Correction to pattern match in ste:1485." date="2010-12-27T19:49:00.448-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-12-27T19:58:09.275-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:19.196-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:208 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:18.675-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:15.525-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:59.974-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" test_ref="oval:org.mitre.oval:tst:1633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2058" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows Mail is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Windows Mail</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_mail"/>
        <description>Microsoft Windows Mail is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T12:32:06.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Corrected regex in ste:3814 to account for both commas and dots, also anchored the boundaries." date="2007-06-15T13:10:00.106-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:59.294-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:52.876-04:00">ACCEPTED</status_change>
            <modified comment="Corrected comment for oval:org.mitre.oval:tst:3506 and updated ste:3814 to match with newer versions of Windows Mail 6.0." date="2010-05-12T11:21:00.138-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-05-12T11:23:48.997-04:00">INTERIM</status_change>
            <modified comment="Added new test to check for Windows Mail 6.1" date="2010-05-12T11:57:00.591-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:05.436-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.275-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.275-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:59.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Windows Mail version 6.0" test_ref="oval:org.mitre.oval:tst:3506"/>
        <criterion comment="Windows Mail version 6.1" test_ref="oval:org.mitre.oval:tst:11318"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6696" version="6" class="vulnerability">
      <metadata>
        <title>Windows MFC Document Title Updating Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3227" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3227"/>
        <description>Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:52.847-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:37:00.947-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:05.350-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:08.689-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:44.681-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:44.681-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:20.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6151" test_ref="oval:org.mitre.oval:tst:11595"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6686" version="9" class="vulnerability">
      <metadata>
        <title>HTML Element Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1260"/>
        <description>The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:18.494-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:45.183-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:07.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:05.498-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:51.313-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.712-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.712-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:20.184-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6686 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.936-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:17.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6653" version="13" class="vulnerability">
      <metadata>
        <title>Windows Media Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2745"/>
        <description>Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitrary code via crafted media content referenced in an HTML document, aka "Windows Media Player Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:20.616-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:28.287-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:43.626-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.494-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.494-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:17.851-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6653 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:53:00.179-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:04.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10251 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-30T10:26:30.362-04:00">INTERIM</status_change>
            <status_change date="2014-06-16T04:00:17.581-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6653 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:12.123-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:16.531-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20961 - MS bulletins for the month of June 2015" date="2015-06-18T10:14:00.489-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-06-18T10:17:12.835-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:46.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Media Player 9 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criterion comment="the version of Wmp.dll is less than 9.0.0.4510" test_ref="oval:org.mitre.oval:tst:21458"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4081" test_ref="oval:org.mitre.oval:tst:21227"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows XP (x64-bit) or Windows Server 2003 (x64-bit)">
          <criteria operator="OR" comment="Windows XP (x64-bit) or Windows Server 2003 (x64-bit)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wwmp.dll is less than 10.0.0.4008" test_ref="oval:org.mitre.oval:tst:20961"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on windows server 2003 x86">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4008" test_ref="oval:org.mitre.oval:tst:21417"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows XP x86 or windows XP (x64-bit)">
          <criteria operator="OR" comment="Windows XP x86 or windows XP (x64-bit)">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criterion comment="the version of Wmp.dll is less than 11.0.5721.5280" test_ref="oval:org.mitre.oval:tst:21412"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista/Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6001.7010" test_ref="oval:org.mitre.oval:tst:21303"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spwmp.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10251"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6001.7118" test_ref="oval:org.mitre.oval:tst:21416"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista /Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6002.18311" test_ref="oval:org.mitre.oval:tst:21253"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Wmp.dll is greater than or equal 11.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21257"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6002.22486" test_ref="oval:org.mitre.oval:tst:21471"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 12 on Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Windows Media Player v12 is installed." definition_ref="oval:org.mitre.oval:def:7384"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Wmp.dll is less than 12.0.7600.16667" test_ref="oval:org.mitre.oval:tst:20189"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmp.dll is greater than or equal 12.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20141"/>
              <criterion comment="The version of Wmp.dll is less than 12.0.7600.20792" test_ref="oval:org.mitre.oval:tst:20478"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6570" version="8" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-3674)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3674"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:12.102-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:37.834-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:10.742-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:37:00.237-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:37:45.242-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:19.874-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:50.025-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:50.025-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:16.549-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6578 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:19.120-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:29.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6570 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:45.998-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:15.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18854" test_ref="oval:org.mitre.oval:tst:10325"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22945" test_ref="oval:org.mitre.oval:tst:11217"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18865" test_ref="oval:org.mitre.oval:tst:11230"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22956" test_ref="oval:org.mitre.oval:tst:11290"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:21026"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16466" test_ref="oval:org.mitre.oval:tst:11033"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20579" test_ref="oval:org.mitre.oval:tst:10797"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6519" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-3673)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3673"/>
        <description>Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:11.285-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:36.101-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:09.430-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:36:00.088-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:37:29.096-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:18.819-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.931-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.931-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:15.109-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:10.718-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6578 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-17T04:00:29.521-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6519 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:56.517-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:15.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18349" test_ref="oval:org.mitre.oval:tst:10560"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22550" test_ref="oval:org.mitre.oval:tst:11161"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18130" test_ref="oval:org.mitre.oval:tst:11275"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22252" test_ref="oval:org.mitre.oval:tst:11036"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18854" test_ref="oval:org.mitre.oval:tst:10325"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22945" test_ref="oval:org.mitre.oval:tst:11217"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18865" test_ref="oval:org.mitre.oval:tst:11230"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22956" test_ref="oval:org.mitre.oval:tst:11290"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:21026"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16466" test_ref="oval:org.mitre.oval:tst:11033"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20579" test_ref="oval:org.mitre.oval:tst:10797"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6421" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>ATL COM Initialization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493"/>
        <description>The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:02.292-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:56.358-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:41.161-05:00">ACCEPTED</status_change>
            <modified comment="Deprecated after consolidating other definitions for the same CVE. The new consolidated definition is oval:org.mitre.oval:def:6716" date="2010-01-03T18:00:11.513-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-03T18:00:11.513-04:00">DEPRECATED</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.946-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10568"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10739"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10428"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10956"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10741"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10559"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10837"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10923"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10592"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10657"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10978"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10876"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10927"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10844"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:11009"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10968"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10708"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10997"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10786"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10822"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10892"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10680"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10951"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10887"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10198"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10986"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10698"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10823"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10819"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10829"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:229" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows 2000 SP4 or later is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2000"/>
        <description>The operating system installed on the system is Microsoft Windows 2000 SP4 or later.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:16.978-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.885-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.915-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:11:20.008-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:40.599-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for SP4 or later and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:27.963-05:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.779-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:42.620-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:39.348-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:27.340-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:229 - added CPE references in several inventories for uniformity" date="2014-04-10T08:25:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:32:03.976-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:37.344-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:2"/>
        <criterion comment="SP4 or later Installed" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6382" version="8" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-3671)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3671" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3671"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3674.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:08.129-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:32.144-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:07.665-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:35:00.638-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:36:50.645-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:15.412-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.244-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.244-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:12.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6578 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:19.296-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:27.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6382 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:49.502-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:12.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18854" test_ref="oval:org.mitre.oval:tst:10325"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22945" test_ref="oval:org.mitre.oval:tst:11217"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18865" test_ref="oval:org.mitre.oval:tst:11230"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22956" test_ref="oval:org.mitre.oval:tst:11290"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:21026"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16466" test_ref="oval:org.mitre.oval:tst:11033"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20579" test_ref="oval:org.mitre.oval:tst:10797"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6263" version="5" class="vulnerability">
      <metadata>
        <title>Local Security Authority Subsystem Service Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2524"/>
        <description>Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:49.596-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:42.254-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:26.750-05:00">ACCEPTED</status_change>
            <modified comment="Added test to check for KB968389 on XP,2003 - Msv1_0.dll greater than or equal to check" date="2009-12-02T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Added tests to check for the installation of KB968389, which is a prerequisite to MS09-059 on Windows XP and 2003 per the security bulletin." date="2009-12-03T17:11:00.230-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-03T17:17:46.238-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:52.245-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:29:00.062-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:30:25.086-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:13.257-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.728-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.728-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:10.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Msv1_0.dll is less than 5.1.2600.3625" test_ref="oval:org.mitre.oval:tst:10744"/>
          <criterion comment="the version of Msv1_0.dll is greater than or equal to 5.1.2600.3592" test_ref="oval:org.mitre.oval:tst:11167"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Msv1_0.dll is less than 5.1.2600.5876" test_ref="oval:org.mitre.oval:tst:10761"/>
          <criterion comment="the version of Msv1_0.dll is greater than or equal to 5.1.2600.5834" test_ref="oval:org.mitre.oval:tst:11012"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x64 SP2, Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is less than 5.2.3790.4587" test_ref="oval:org.mitre.oval:tst:10736"/>
          <criterion comment="the version of Msv1_0.dll is greater than or equal to 5.2.3790.4530" test_ref="oval:org.mitre.oval:tst:11220"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10848"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6000.16926" test_ref="oval:org.mitre.oval:tst:10874"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10107"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6000.21125" test_ref="oval:org.mitre.oval:tst:10875"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10976"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6001.18330" test_ref="oval:org.mitre.oval:tst:10614"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10982"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6001.22518" test_ref="oval:org.mitre.oval:tst:10687"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10008"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6002.18111" test_ref="oval:org.mitre.oval:tst:10590"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10174"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6002.22223" test_ref="oval:org.mitre.oval:tst:10399"/>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Msv1_0.dll version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20995"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.1.7600.16420" test_ref="oval:org.mitre.oval:tst:10985"/>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Msv1_0.dll version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20123"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.1.7600.20524" test_ref="oval:org.mitre.oval:tst:10511"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6186" version="8" class="vulnerability">
      <metadata>
        <title>Integer Overflow in X.509 Object Identifiers Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2511"/>
        <description>Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:07.588-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:39.286-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:24.133-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6186 - LDR version criteria are added for Vista &amp; 2008, and also added non-root criterion comments" date="2011-10-04T13:16:00.750-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:19:21.125-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:21.159-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.978-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.978-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:09.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6186 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:15.270-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:09.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msasn1.dll is less than 5.0.2195.7334" test_ref="oval:org.mitre.oval:tst:10655"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.3624" test_ref="oval:org.mitre.oval:tst:10905"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.5875" test_ref="oval:org.mitre.oval:tst:10731"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of msasn1.dll is less than 5.2.3790.4584" test_ref="oval:org.mitre.oval:tst:10013"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6000.16922" test_ref="oval:org.mitre.oval:tst:10512"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44028"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6000.21122" test_ref="oval:org.mitre.oval:tst:43659"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6001.18326" test_ref="oval:org.mitre.oval:tst:10835"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44222"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6001.22515" test_ref="oval:org.mitre.oval:tst:43926"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6002.18106" test_ref="oval:org.mitre.oval:tst:10818"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:44044"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6002.22218" test_ref="oval:org.mitre.oval:tst:44105"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.1.7600.16415" test_ref="oval:org.mitre.oval:tst:10587"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:10901"/>
              <criterion comment="the version of msasn1.dll is less than 6.1.7600.20518" test_ref="oval:org.mitre.oval:tst:10706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5842" version="8" class="vulnerability">
      <metadata>
        <title>Null Truncation in X.509 Common Name Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2510"/>
        <description>The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:06.961-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:26.396-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:11.936-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5842 - LDR version criteria are added for Vista &amp; 2008, and also added non-root criterion comments" date="2011-10-04T13:16:00.750-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:19:19.322-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:14.969-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.665-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.665-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:06.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5842 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:14.011-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:03.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msasn1.dll is less than 5.0.2195.7334" test_ref="oval:org.mitre.oval:tst:10655"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.3624" test_ref="oval:org.mitre.oval:tst:10905"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.5875" test_ref="oval:org.mitre.oval:tst:10731"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of msasn1.dll is less than 5.2.3790.4584" test_ref="oval:org.mitre.oval:tst:10013"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6000.16922" test_ref="oval:org.mitre.oval:tst:10512"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44028"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6000.21122" test_ref="oval:org.mitre.oval:tst:43659"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6001.18326" test_ref="oval:org.mitre.oval:tst:10835"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44222"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6001.22515" test_ref="oval:org.mitre.oval:tst:43926"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6002.18106" test_ref="oval:org.mitre.oval:tst:10818"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:44044"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6002.22218" test_ref="oval:org.mitre.oval:tst:44105"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.1.7600.16415" test_ref="oval:org.mitre.oval:tst:10587"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:10901"/>
              <criterion comment="the version of msasn1.dll is less than 6.1.7600.20518" test_ref="oval:org.mitre.oval:tst:10706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5716" version="8" class="vulnerability">
      <metadata>
        <title>Microsoft .NET Framework Pointer Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0090"/>
        <description>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:55.227-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:21.996-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:07.631-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T17:59:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-01T18:00:44.235-05:00">INTERIM</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:00:00.766-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.229-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.547-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-21T04:00:37.997-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5716 - Updated defs for MS09-061 - updated criteria and modified the GDR/LDR format." date="2011-01-31T17:30:00.645-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:33:02.153-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:52.645-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.368-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.368-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:05.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5716 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:18.399-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:01.746-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 1.1 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of Mscorlib.dll is less than 1.1.4322.2443" test_ref="oval:org.mitre.oval:tst:10854"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:85" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2000"/>
        <description>The operating system installed on the system is Microsoft Windows 2000.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.142-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:03:27.160-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:53.257-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.718-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:29:31.741-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:24.735-04:00">ACCEPTED</status_change>
            <modified comment="Changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:01:19.119-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:2"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29493" version="3" class="vulnerability">
      <metadata>
        <title>OpenType font driver vulnerability - CVE-2015-2426 (MS15-078)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2426"/>
        <description>Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:33:46.957-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:57.541-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:28.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.243" test_ref="oval:org.mitre.oval:tst:141149"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29487" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2388 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-2388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2388" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1738.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:53.088-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:57.248-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:27.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29470" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2414 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2414" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:13.594-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:56.809-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:27.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29454" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-2402 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2402" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:58.714-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:56.432-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:26.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29436" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of privilege vulnerability - CVE-2015-2363 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2363"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:54.125-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.626-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29431" version="3" class="vulnerability">
      <metadata>
        <title>Windows installer EoP vulnerability - CVE-2015-2371 (MS15-074)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2371"/>
        <description>The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a custom action script associated with a .msi package, aka "Windows Installer EoP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:27:30.824-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.162-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of msi.dll is less than 4.5.6002.19424" test_ref="oval:org.mitre.oval:tst:140643"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of msi.dll is greater than or equal to 4.5.6002.23000" test_ref="oval:org.mitre.oval:tst:140917"/>
              <criterion comment="Check if the version of msi.dll is less than 4.5.6002.23730" test_ref="oval:org.mitre.oval:tst:141315"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of msi.dll is less than 5.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141258"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of msi.dll is greater than or equal to 5.0.7601.23000" test_ref="oval:org.mitre.oval:tst:140322"/>
              <criterion comment="Check if the version of msi.dll is less than 5.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141164"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of msi.dll is less than 5.0.9600.17905" test_ref="oval:org.mitre.oval:tst:140784"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msi.dll is less than 4.5.6002.23731" test_ref="oval:org.mitre.oval:tst:141276"/>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of msi.dll is less than 5.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141175"/>
              <criterion comment="Check if the version of msi.dll is greater than or equal to 5.0.9200.21000" test_ref="oval:org.mitre.oval:tst:141015"/>
            </criteria>
            <criterion comment="Check if the version of msi.dll is less than 5.0.9200.17412" test_ref="oval:org.mitre.oval:tst:141240"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29422" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer information disclosure vulnerability - CVE-2015-2413 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2413" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2413" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:56.062-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:54.512-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29414" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1738 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1738" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2388.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:08.650-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:54.296-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:24.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29406" version="3" class="vulnerability">
      <metadata>
        <title>Hyper-V system data structure vulnerability - CVE-2015-2362 (MS15-068)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2362" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2362"/>
        <description>Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS by leveraging guest OS privileges, aka "Hyper-V System Data Structure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:38:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:18:46.949-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:54.045-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:24.594-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8.1 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="8.1 / 2k12">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of vmicvss.dll is less than 6.3.9600.17723" test_ref="oval:org.mitre.oval:tst:141277"/>
        </criteria>
        <criteria operator="AND" comment="2k8 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of vmicvss.dll is less than 6.0.6002.19378" test_ref="oval:org.mitre.oval:tst:141275"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of vmicvss.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141253"/>
              <criterion comment="Check if the version of vmicvss.dll is less than 6.0.6002.23684" test_ref="oval:org.mitre.oval:tst:141040"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="R2 x64 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of vmicvss.dll is less than 6.1.7601.18844" test_ref="oval:org.mitre.oval:tst:140965"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of vmicvss.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141216"/>
              <criterion comment="Check if the version of vmicvss.dll is less than 6.1.7601.23045" test_ref="oval:org.mitre.oval:tst:141089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 (x64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of vmicvss.dll is less than 6.2.9200.17361" test_ref="oval:org.mitre.oval:tst:141232"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of vmicvss.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:141131"/>
              <criterion comment="Check if the version of vmicvss.dll is less than 6.2.9200.21473" test_ref="oval:org.mitre.oval:tst:140470"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29395" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2389 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2389" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1733 and CVE-2015-2411.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:42.224-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:53.843-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:24.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29360" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2422 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2422" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, and CVE-2015-2406.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:11.475-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:52.125-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:23.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29357" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2404 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2404" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:01.266-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:51.680-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:22.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29355" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-2421 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2421" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:05.529-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:50.170-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:22.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29332" version="3" class="vulnerability">
      <metadata>
        <title>ATMFD.DLL Memory corruption vulnerability - CVE-2015-2387 (MS15-077)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2387"/>
        <description>ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "ATMFD.DLL Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:32:13.105-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:49.766-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.242" test_ref="oval:org.mitre.oval:tst:140421"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.242" test_ref="oval:org.mitre.oval:tst:141178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29327" version="3" class="vulnerability">
      <metadata>
        <title>Windows RPC elevation of privilege vulnerability - CVE-2015-2370 (MS15-076)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2370"/>
        <description>The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prevent DCE/RPC connection reflection, which allows local users to gain privileges via a crafted application, aka "Windows RPC Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:30:38.407-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:49.319-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 5.2.3790.5669" test_ref="oval:org.mitre.oval:tst:141239"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8(x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.0.6002.19431" test_ref="oval:org.mitre.oval:tst:141076"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135821"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.0.6002.23737" test_ref="oval:org.mitre.oval:tst:140349"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.1.7601.18909" test_ref="oval:org.mitre.oval:tst:140560"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135603"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.1.7601.23112" test_ref="oval:org.mitre.oval:tst:141041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/ Server 2012 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8/ Server 2012 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.17420" test_ref="oval:org.mitre.oval:tst:140691"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135794"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.21529" test_ref="oval:org.mitre.oval:tst:141299"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 6.3.9600.17918" test_ref="oval:org.mitre.oval:tst:140736"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29324" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2397 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2397" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:24.103-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:48.951-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29316" version="3" class="vulnerability">
      <metadata>
        <title>Jscript9 Memory corruption vulnerability - CVE-2015-2419 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2419" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2419" source="CVE"/>
        <description>JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:21.268-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:48.651-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:20.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29296" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2425 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2425" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2425" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2384.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:28.790-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.724-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29295" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1729 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1729" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:17.942-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.501-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29292" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2408 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2408" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2401.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:02.935-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.245-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.108-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29280" version="3" class="vulnerability">
      <metadata>
        <title>Windows DLL remote code execution vulnerability - CVE-2015-2368 (MS15-069)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2368"/>
        <description>Untrusted search path vulnerability in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Windows DLL Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T10:06:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:20:31.123-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:29280 - Removed unneeded file checks" date="2015-07-27T14:44:00.654-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T04:01:30.053-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criterion comment="Check if the version of wksprt.exe is less than 6.3.9600.17901" test_ref="oval:org.mitre.oval:tst:141280"/>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 (x86) and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <criterion comment="Check if the version of atlthunk.dll is less than 6.3.9600.17415" test_ref="oval:org.mitre.oval:tst:141198"/>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/2k12 R2(64 bit) and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2 (x64)">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version Atlthunk.dll is less than 6.3.9600.17670 (SysWow64)" test_ref="oval:org.mitre.oval:tst:141270"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29278" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2385 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2385" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:38.192-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.768-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:18.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29247" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2391 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-2391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2391" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:32.143-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.501-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:17.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29219" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2411 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2411" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1733 and CVE-2015-2389.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:07.261-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.027-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:17.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29198" version="3" class="vulnerability">
      <metadata>
        <title>OLE Elevation of privilege vulnerability - CVE-2015-2417 (MS15-075)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2417"/>
        <description>OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2416.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:29:09.429-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.570-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 5.2.3790.5663" test_ref="oval:org.mitre.oval:tst:140974"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.19435" test_ref="oval:org.mitre.oval:tst:140324"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141237"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.23743" test_ref="oval:org.mitre.oval:tst:140765"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.18896" test_ref="oval:org.mitre.oval:tst:141296"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141207"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.23099" test_ref="oval:org.mitre.oval:tst:140818"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.21524" test_ref="oval:org.mitre.oval:tst:141136"/>
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:140969"/>
            </criteria>
            <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.17414" test_ref="oval:org.mitre.oval:tst:141309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 6.3.9600.17905" test_ref="oval:org.mitre.oval:tst:140986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29164" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2383 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2383" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2384 and CVE-2015-2425.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:51.318-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.334-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29159" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2412 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2412" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:15.003-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.142-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29156" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2365 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2365"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:49.098-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:44.843-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:15.662-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29149" version="3" class="vulnerability">
      <metadata>
        <title>DLL planting remote code execution vulnerability - CVE-2015-2369 (MS15-069)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2369" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2369"/>
        <description>Untrusted search path vulnerability in Windows Media Device Manager in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rtf file, aka "DLL Planting Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T10:06:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:20:29.893-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:29149 - Removed unneeded file checks" date="2015-07-27T14:42:00.063-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T04:01:02.218-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of cewmdm.dll is less than 12.0.7601.18872" test_ref="oval:org.mitre.oval:tst:141176"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of cewmdm.dll is greater than or equal to 12.0.7601.23000" test_ref="oval:org.mitre.oval:tst:141218"/>
              <criterion comment="Check if the version of cewmdm.dll is less than 12.0.7601.23075" test_ref="oval:org.mitre.oval:tst:140851"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2003(x86) and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of cewmdm.dll is less than 10.0.3790.4011" test_ref="oval:org.mitre.oval:tst:140828"/>
        </criteria>
        <criteria operator="AND" comment="2k3(x64) and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <criterion comment="Check if the version of wcewmdm.dll is less than 10.0.3790.4011" test_ref="oval:org.mitre.oval:tst:141308"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of cewmdm.dll is less than 11.0.6002.19403" test_ref="oval:org.mitre.oval:tst:141071"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of cewmdm.dll is greater than or equal to 11.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141312"/>
              <criterion comment="Check if the version of cewmdm.dll is less than 11.0.6002.23710" test_ref="oval:org.mitre.oval:tst:141109"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29147" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1743 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1743" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1748.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:19.881-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.948-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:12.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29145" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Null pointer dereference vulnerability - CVE-2015-1721 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1721"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer Dereference Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:15.663-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.736-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:12.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29142" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1739 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1739" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:42.416-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.092-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:11.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29128" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2366 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2366"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:55.121-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.840-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:14.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29124" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Object use after free vulnerability - CVE-2015-1724 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1724"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Object Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:31.348-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.463-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:08.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29123" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1740 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1740" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1744, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:36.047-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.166-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:08.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29119" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1742 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1742" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1742" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1747, CVE-2015-1750, and CVE-2015-1753.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:08.967-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.017-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:07.960-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29118" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel use after free vulnerability – CVE-2015-1720 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1720"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:13.516-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:43.770-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:07.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29115" version="3" class="vulnerability">
      <metadata>
        <title>Exchange Cross-Site Request Forgery vulnerability - CVE-2015-1771 (MS15-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1771"/>
        <description>Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:51.667-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:17.668-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:53.001-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.41" test_ref="oval:org.mitre.oval:tst:139078"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU8 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 8 is installed" definition_ref="oval:org.mitre.oval:def:29138"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1076.011" test_ref="oval:org.mitre.oval:tst:139030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29113" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1735 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1735" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1735" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1740, CVE-2015-1744, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:32.864-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:43.444-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:06.735-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29093" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel information disclosure vulnerability – CVE-2015-1719 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1719"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to obtain sensitive information from kernel memory via a crafted application, aka "Microsoft Windows Kernel Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:33.625-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:42.325-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:03.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29087" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2410 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2410" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted stylesheet, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:46.838-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.376-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:14.068-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29081" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1687 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1687" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:05.893-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:41.702-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:01.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29076" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1766 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1766" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:13.617-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:40.866-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:00.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29075" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer XSS filter bypass vulnerability - CVE-2015-2398 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2398" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:44.325-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.058-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:13.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29067" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Station use after free vulnerability - CVE-2015-1723 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1723" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1723"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Station Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:17.588-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:39.183-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:57.483-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29061" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1753 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1753" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1742, CVE-2015-1747, and CVE-2015-1750.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:23.236-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:39.061-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:57.103-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29060" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1751 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1751" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:03.315-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.875-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.937-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29057" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1747 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1747" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1742, CVE-2015-1750, and CVE-2015-1753.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:27.051-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.734-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29050" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Pool buffer overflow vulnerability - CVE-2015-1727 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1727"/>
        <description>Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Pool Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:26.307-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.464-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.042-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29033" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1732 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1732" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1742, CVE-2015-1747, CVE-2015-1750, and CVE-2015-1753.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:20.730-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.232-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:53.961-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29016" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-1685 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1685" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1685" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:12.160-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.856-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:37.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29015" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1767 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1767" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2401 and CVE-2015-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:33.802-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:42.386-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29010" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2403 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-2403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2403" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:25.540-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:42.119-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29009" version="4" class="vulnerability">
      <metadata>
        <title>MSXML3 same origin policy SFB vulnerability - CVE-2015-1646 (MS15-039)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft XML Core Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1646" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1646"/>
        <description>Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-24T20:56:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-12T14:22:30.361-04:00">DRAFT</status_change>
            <status_change date="2015-06-01T04:00:23.144-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:45.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 vulnerable version">
          <criteria operator="OR" comment="Server (2003 - x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="Check if the version of msxml3.dll is less than 8.100.1057.0" test_ref="oval:org.mitre.oval:tst:138415"/>
        </criteria>
        <criteria operator="AND" comment="Vista/ 2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista /2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="Check if the version of msxml3.dll is less than 8.100.5010.0" test_ref="oval:org.mitre.oval:tst:138091"/>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msxml3.dll is less than 8.110.7601.18782" test_ref="oval:org.mitre.oval:tst:138590"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Msxml3.dll is greater than or equal to 8.110.7601.22000" test_ref="oval:org.mitre.oval:tst:79072"/>
              <criterion comment="Check if the version of msxml3.dll is less than 8.110.7601.22986" test_ref="oval:org.mitre.oval:tst:138589"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29005" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1748 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1748" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1743.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:16.086-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:37.151-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:49.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29001" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1676 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1676"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1677, CVE-2015-1678, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:23.410-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.607-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29000" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1658 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1658" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1706, CVE-2015-1711, CVE-2015-1717, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:28.786-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.446-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28994" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2360 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2360"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:21.750-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:36.298-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:49.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28993" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1717 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1717" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1711, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:15.134-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.271-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28990" version="3" class="vulnerability">
      <metadata>
        <title>OLE Elevation of privilege vulnerability - CVE-2015-2416 (MS15-075)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2416"/>
        <description>OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:29:07.182-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:41.628-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 5.2.3790.5663" test_ref="oval:org.mitre.oval:tst:140974"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.19435" test_ref="oval:org.mitre.oval:tst:140324"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141237"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.23743" test_ref="oval:org.mitre.oval:tst:140765"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.18896" test_ref="oval:org.mitre.oval:tst:141296"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141207"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.23099" test_ref="oval:org.mitre.oval:tst:140818"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.21524" test_ref="oval:org.mitre.oval:tst:141136"/>
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:140969"/>
            </criteria>
            <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.17414" test_ref="oval:org.mitre.oval:tst:141309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 6.3.9600.17905" test_ref="oval:org.mitre.oval:tst:140986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28984" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1709 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1709" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1709" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:22.678-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.731-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:35.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28968" version="3" class="vulnerability">
      <metadata>
        <title>Elevation of privilege vulnerability in Netlogon - CVE-2015-2374 (MS15-071)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2374"/>
        <description>The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remote attackers to discover credentials by leveraging certain PDC access and spoofing the BDC role in a PDC communication channel, aka "Elevation of Privilege Vulnerability in Netlogon."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:36:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:22:16.859-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:41.383-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:11.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable versions">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          </criteria>
          <criterion comment="Check if the version of netlogon.dll is less than 5.2.3790.5648" test_ref="oval:org.mitre.oval:tst:141284"/>
        </criteria>
        <criteria operator="AND" comment="2k8(x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="2K8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of netlogon.dll is less than 6.0.6002.19409" test_ref="oval:org.mitre.oval:tst:141034"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of netlogon.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138425"/>
              <criterion comment="Check if the version of netlogon.dll is less than 6.0.6002.23716" test_ref="oval:org.mitre.oval:tst:141196"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="R2 (x64 / ia64) and vulnerable file versions">
          <criteria operator="OR" comment="R2 (x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of netlogon.dll is less than 6.1.7601.18880" test_ref="oval:org.mitre.oval:tst:141268"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of netlogon.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138356"/>
              <criterion comment="Check if the version of netlogon.dll is less than 6.1.7601.23083" test_ref="oval:org.mitre.oval:tst:140963"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Server 2012 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of netlogon.dll is less than 6.2.9200.17395" test_ref="oval:org.mitre.oval:tst:140993"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of netlogon.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138191"/>
              <criterion comment="Check if the version of netlogon.dll is less than 6.2.9200.21506" test_ref="oval:org.mitre.oval:tst:141189"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Server 2012 R2 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          <criterion comment="Check if the version of netlogon.dll is less than 6.3.9600.17901" test_ref="oval:org.mitre.oval:tst:141157"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28951" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1705 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1705" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1705" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1689.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:24.391-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.424-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:35.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28950" version="4" class="vulnerability">
      <metadata>
        <title>Windows forms elevation of privilege vulnerability - CVE-2015-1673 (MS15-048)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1673"/>
        <description>The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbitrary code via a crafted partial-trust application, aka "Windows Forms Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:34:59.080-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.089-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:34.795-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28950 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:16.687-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2512" test_ref="oval:org.mitre.oval:tst:138654"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8655" test_ref="oval:org.mitre.oval:tst:138616"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.3667" test_ref="oval:org.mitre.oval:tst:138084"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.4257" test_ref="oval:org.mitre.oval:tst:138542"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.6427" test_ref="oval:org.mitre.oval:tst:138639"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138859"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.5491" test_ref="oval:org.mitre.oval:tst:137946"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.2057" test_ref="oval:org.mitre.oval:tst:138799"/>
              <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80817"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.1032" test_ref="oval:org.mitre.oval:tst:138641"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36287" test_ref="oval:org.mitre.oval:tst:138838"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34251" test_ref="oval:org.mitre.oval:tst:138683"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36286" test_ref="oval:org.mitre.oval:tst:138687"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34250" test_ref="oval:org.mitre.oval:tst:138511"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36286" test_ref="oval:org.mitre.oval:tst:138687"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34250" test_ref="oval:org.mitre.oval:tst:138511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28948" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1755 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1755" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1736, and CVE-2015-1737.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:28.677-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:34.461-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:45.797-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28938" version="3" class="vulnerability">
      <metadata>
        <title>VBScript Memory corruption vulnerability - CVE-2015-2372 (MS15-065 and MS15-066)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft VBScript 5.6</product>
          <product>Microsoft VBScript 5.7</product>
          <product>Microsoft VBScript 5.8</product>
        </affected>
        <reference ref_id="CVE-2015-2372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2372" source="CVE"/>
        <description>vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:31.155-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:40.445-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:10.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <criterion comment="vbscript.dll 5.6 or later is installed" test_ref="oval:org.mitre.oval:tst:100534"/>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of VBScript.dll is less than 5.6.0.8856" test_ref="oval:org.mitre.oval:tst:141230"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <criterion comment="Vbscript.dll 5.7 or later is installed" test_ref="oval:org.mitre.oval:tst:11558"/>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23712" test_ref="oval:org.mitre.oval:tst:140314"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.19405" test_ref="oval:org.mitre.oval:tst:141294"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23712" test_ref="oval:org.mitre.oval:tst:140314"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Internet Explorer 7 is installed" test_ref="oval:org.mitre.oval:tst:178"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <criterion comment="Vbscript.dll 5.8 or later is installed" test_ref="oval:org.mitre.oval:tst:11329"/>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2 + IE 8 vulnerable version">
              <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="2k3 and vulnerable version">
                  <criteria operator="OR" comment="2K3">
                    <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                    <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23707" test_ref="oval:org.mitre.oval:tst:140824"/>
                </criteria>
                <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
                  <criteria operator="OR" comment="Vista / 2K8">
                    <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                    <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19652" test_ref="oval:org.mitre.oval:tst:141188"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23707" test_ref="oval:org.mitre.oval:tst:140824"/>
                      <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                    </criteria>
                  </criteria>
                </criteria>
                <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  </criteria>
                  <criteria operator="OR" comment="vulnerable file version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18896" test_ref="oval:org.mitre.oval:tst:141265"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.23099" test_ref="oval:org.mitre.oval:tst:140984"/>
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.7601.23000" test_ref="oval:org.mitre.oval:tst:138193"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 9 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17174" test_ref="oval:org.mitre.oval:tst:140884"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20785" test_ref="oval:org.mitre.oval:tst:141278"/>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 9 is installed" test_ref="oval:org.mitre.oval:tst:42359"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <criterion comment="Check if Microsoft Internet Explorer 10 is installed" test_ref="oval:org.mitre.oval:tst:80429"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17410" test_ref="oval:org.mitre.oval:tst:140995"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21521" test_ref="oval:org.mitre.oval:tst:141291"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/2k8 R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/2k8 R2/Win8.1/2k12 R2 and vulnerable file version">
                <criteria operator="AND" comment="Win7 x86 and vulnerable version">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17909" test_ref="oval:org.mitre.oval:tst:141182"/>
                </criteria>
                <criteria operator="AND" comment="Win7 x64 / Server 2008 R2 and vulnerable version">
                  <criteria operator="OR" comment="Win 7 / R2">
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17910" test_ref="oval:org.mitre.oval:tst:141085"/>
                </criteria>
                <criteria operator="AND" comment="Win 8.1  / Server 2012 R2 and vulnerable version">
                  <criteria operator="OR" comment="Win 7 / R2">
                    <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                    <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                    <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17905" test_ref="oval:org.mitre.oval:tst:140873"/>
                </criteria>
              </criteria>
              <criterion comment="Check if Microsoft Internet Explorer 11 is installed" test_ref="oval:org.mitre.oval:tst:87142"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28936" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1699 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1699"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, and CVE-2015-1698.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:49.383-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:30.836-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:34.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28932" version="3" class="vulnerability">
      <metadata>
        <title>Service control manager elevation of privilege vulnerability - CVE-2015-1702 (MS15-050)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1702"/>
        <description>The Service Control Manager (SCM) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Service Control Manager Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:39:47">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:37:09.571-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:30.416-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:33.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of services.exe is less than 6.0.6002.19369" test_ref="oval:org.mitre.oval:tst:138682"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138469"/>
              <criterion comment="Check if the version of services.exe is less than 6.0.6002.23677" test_ref="oval:org.mitre.oval:tst:138468"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of services.exe is less than 6.1.7601.18829" test_ref="oval:org.mitre.oval:tst:138200"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138798"/>
              <criterion comment="Check if the version of services.exe is less than 6.1.7601.23033" test_ref="oval:org.mitre.oval:tst:138581"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of services.exe is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138750"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138360"/>
              <criterion comment="Check if the version of services.exe is less than 6.2.9200.21456" test_ref="oval:org.mitre.oval:tst:138573"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of services.exe is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:137869"/>
        </criteria>
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28928" version="3" class="vulnerability">
      <metadata>
        <title>Exchange HTML injection vulnerability - CVE-2015-2359 (MS15-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2359"/>
        <description>Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Exchange HTML Injection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:52.070-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:14.350-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:50.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 8 is installed" definition_ref="oval:org.mitre.oval:def:29138"/>
        <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1076.011" test_ref="oval:org.mitre.oval:tst:139030"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28924" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint page content vulnerabilities – CVE-2015-1700 (MS15-047)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Server 2007</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1700"/>
        <description>Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T20:21:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:09:54.328-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-06-15T04:00:30.063-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:33.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint 2007 and vulnerable file versions">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="Check if the version of Microsoft.SharePoint.Portal.dll is less than 12.0.6721.5000" test_ref="oval:org.mitre.oval:tst:137831"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of Microsoft.office.policy.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138630"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2010 / 2010 SP1">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138555"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4719.1002" test_ref="oval:org.mitre.oval:tst:138608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2313" version="12" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2007 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office SharePoint Server 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2007"/>
        <description>Microsoft Office SharePoint Server 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:51.975-04:00">DRAFT</status_change>
            <status_change date="2007-10-26T10:00:30.934-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:08.127-05:00">ACCEPTED</status_change>
            <modified comment="Changed datatype from version to string." date="2008-08-28T13:32:00.278-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-08-28T13:44:16.491-04:00">INTERIM</status_change>
            <status_change date="2008-09-15T04:00:21.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:38.747-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:18.536-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.072-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.072-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:00.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:25.573-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:03.519-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:36.194-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - removed Microsoft Exchange Server 2003 from inventory" date="2015-06-05T09:04:00.152-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-06-05T09:06:27.662-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:42.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:4279"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28917" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1718 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1718" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1711, and CVE-2015-1717.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:15:59.485-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.917-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:32.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28910" version="4" class="vulnerability">
      <metadata>
        <title>Windows Media Player RCE via DataObject vulnerability - CVE-2015-1728 (MS15-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1728"/>
        <description>Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows Media Player RCE via DataObject Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T13:23:15">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:17:11.575-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20961 - MS bulletins for the month of June 2015" date="2015-06-18T10:14:00.489-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-06T04:00:32.407-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:42.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Media Player 9">
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criterion comment="the version of Wmp.dll is less than 9.0.0.4513" test_ref="oval:org.mitre.oval:tst:138941"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on windows server 2003 x86">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4011" test_ref="oval:org.mitre.oval:tst:138849"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista /Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6002.19378" test_ref="oval:org.mitre.oval:tst:138461"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Wmp.dll is greater than or equal 11.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21257"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6002.23684" test_ref="oval:org.mitre.oval:tst:138068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 12 on Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Windows Media Player v12 is installed." definition_ref="oval:org.mitre.oval:def:7384"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Wmp.dll is less than 12.0.7601.18840" test_ref="oval:org.mitre.oval:tst:138814"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmp.dll is greater than or equal 12.0.7601.22000" test_ref="oval:org.mitre.oval:tst:138964"/>
              <criterion comment="The version of Wmp.dll is less than 12.0.7601.23041" test_ref="oval:org.mitre.oval:tst:138905"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows Server 2003 (x64-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wwmp.dll is less than 10.0.0.4011" test_ref="oval:org.mitre.oval:tst:20961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7384" version="15" class="inventory">
      <metadata>
        <title>Windows Media Player v12 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Windows Media Player 12</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:12"/>
        <description>Windows Media Player v12 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:20.441-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:47.820-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:53.335-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - On definition oval:org.mitre.oval:def:7384  I changed the affected platform from &quot;Microsoft Windows 2008&quot; to &quot;Microsoft Windows Server 2008&quot;" date="2011-05-12T10:52:00.860-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2011-05-12T10:58:08.668-04:00">INTERIM</status_change>
            <status_change date="2011-05-30T04:00:53.617-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:25.594-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:25.649-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.509-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.509-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:57.287-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - inventory for Windows Media Player 12" date="2013-09-13T13:51:00.711-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:52:27.920-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:37.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:86182 - replaced all similar objects with oval:org.mitre.oval:obj:26224" date="2014-04-10T08:55:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:58:20.278-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:40.186-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:26.566-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:28.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 12.0.0.0" test_ref="oval:org.mitre.oval:tst:86727"/>
        <criterion comment="Check if Windows Media Player version is less than 13.0.0.0" test_ref="oval:org.mitre.oval:tst:86182"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2172" version="9" class="inventory">
      <metadata>
        <title>Windows Media Player v10 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player 10</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:10"/>
        <description>Windows Media Player v10 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.378-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.729-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:32.988-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:746 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:18.161-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:09.298-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - inventory for Windows Media Player 10" date="2013-09-13T13:48:00.518-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:49:22.528-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:18.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:26.003-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 10.0.0.0" test_ref="oval:org.mitre.oval:tst:86658"/>
        <criterion comment="Check if Windows Media Player version is less than 11.0.0.0" test_ref="oval:org.mitre.oval:tst:86603"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2147" version="11" class="inventory">
      <metadata>
        <title>Windows Media Player v9 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:9"/>
        <description>Windows Media Player v9 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.096-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.363-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.263-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:37.426-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.606-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:746 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:18.431-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:08.945-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - inventory for Windows Media Player 9" date="2013-09-13T13:46:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:48:00.391-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:18.559-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:86573 - replaced all similar objects with oval:org.mitre.oval:obj:26224" date="2014-04-10T08:55:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:58:19.904-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:00:10.909-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:27.374-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 9.0.0.0" test_ref="oval:org.mitre.oval:tst:86573"/>
        <criterion comment="Check if Windows Media Player version is less than 10.0.0.0" test_ref="oval:org.mitre.oval:tst:86682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2126" version="11" class="inventory">
      <metadata>
        <title>Windows Media Player v11 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Windows Media Player 11</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:11"/>
        <description>Windows Media Player v11 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.057-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.049-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:44.929-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2581 - On definition oval:org.mitre.oval:def:7384  I changed the affected platform from &quot;Microsoft Windows 2008&quot; to &quot;Microsoft Windows Server 2008&quot;" date="2011-05-12T10:52:00.860-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2011-05-12T10:58:12.639-04:00">INTERIM</status_change>
            <status_change date="2011-05-30T04:00:53.060-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2126 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:42.382-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.259-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2126 - inventory for Windows Media Player 11" date="2013-09-13T13:49:00.798-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:51:09.932-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:17.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:86659 - replaced all similar objects with oval:org.mitre.oval:obj:26224" date="2014-04-10T08:55:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:58:20.096-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:00:10.276-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2126 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:26.307-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:09.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 11.0.0.0" test_ref="oval:org.mitre.oval:tst:86659"/>
        <criterion comment="Check if Windows Media Player version is less than 12.0.0.0" test_ref="oval:org.mitre.oval:tst:86623"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28895" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1668 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1668" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:04.735-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:24.960-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28889" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1736 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1736" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1737, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:29.962-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:32.196-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:39.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28876" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1677 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1677"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1678, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:20.752-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.368-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:31.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28865" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1660 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1660" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:20.026-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:24.159-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.437-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28863" version="3" class="vulnerability">
      <metadata>
        <title>NETLOGON spoofing vulnerability - CVE-2015-0005 (MS15-027)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0005"/>
        <description>The NETLOGON service in Microsoft Windows Server 2003 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2, when a Domain Controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive session information, by running a crafted application and leveraging the ability to sniff network traffic, aka "NETLOGON Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T08:56:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:24:59.158-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:17.432-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:27.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable versions">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          </criteria>
          <criterion comment="Check if the version of netlogon.dll is less than 5.2.3790.5551" test_ref="oval:org.mitre.oval:tst:138177"/>
        </criteria>
        <criteria operator="AND" comment="2k8(x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="2K8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of netlogon.dll is less than 6.0.6002.19319" test_ref="oval:org.mitre.oval:tst:137821"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of netlogon.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138425"/>
              <criterion comment="Check if the version of netlogon.dll is less than 6.0.6002.23629" test_ref="oval:org.mitre.oval:tst:138106"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="R2 (x64 / ia64) and vulnerable file versions">
          <criteria operator="OR" comment="R2 (x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of netlogon.dll is less than 6.1.7601.18759" test_ref="oval:org.mitre.oval:tst:138294"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of netlogon.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138356"/>
              <criterion comment="Check if the version of netlogon.dll is less than 6.1.7601.22966" test_ref="oval:org.mitre.oval:tst:138407"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Server 2012 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of netlogon.dll is less than 6.2.9200.17273" test_ref="oval:org.mitre.oval:tst:138273"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of netlogon.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138191"/>
              <criterion comment="Check if the version of netlogon.dll is less than 6.2.9200.21391" test_ref="oval:org.mitre.oval:tst:138015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Server 2012 R2 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          <criterion comment="Check if the version of netlogon.dll is less than 6.3.9600.17678" test_ref="oval:org.mitre.oval:tst:138057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28861" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1666 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1666" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1652.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:18.735-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:23.867-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.054-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28848" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1744 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1744" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1744" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:25.941-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:30.250-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:37.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28844" version="3" class="vulnerability">
      <metadata>
        <title>Impersonation level check elevation of privilege vulnerability - CVE-2015-0075 (MS15-025)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0075"/>
        <description>The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Impersonation Level Check Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:18:59.294-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.674-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if version of Fltmgr.sys is less than 5.2.3790.5107" test_ref="oval:org.mitre.oval:tst:138447"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138397"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:137988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22943" test_ref="oval:org.mitre.oval:tst:138117"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18738" test_ref="oval:org.mitre.oval:tst:138289"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28843" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1624 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1624" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:27.309-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.411-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28840" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1712 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1712" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1712" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1691.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:05.231-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.634-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28836" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0100 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-0100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0100" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:37.833-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.222-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.076-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28834" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2406 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2406" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:27.990-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:39.346-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:10.001-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28831" version="3" class="vulnerability">
      <metadata>
        <title>NtCreateTransactionManager type confusion vulnerability - CVE-2015-1643 (MS15-038)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1643"/>
        <description>Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "NtCreateTransactionManager Type Confusion Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T12:36:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:20:34.323-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:22.974-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:21.658-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.0.6002.19331" test_ref="oval:org.mitre.oval:tst:138203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138245"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.0.6002.23639" test_ref="oval:org.mitre.oval:tst:138205"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.1.7601.18777" test_ref="oval:org.mitre.oval:tst:137624"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138543"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.1.7601.22981" test_ref="oval:org.mitre.oval:tst:138480"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.2.9200.17291" test_ref="oval:org.mitre.oval:tst:138549"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138180"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.2.9200.21408" test_ref="oval:org.mitre.oval:tst:138574"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/Server 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Clfsw32.dll is less than 6.3.9600.17719" test_ref="oval:org.mitre.oval:tst:138112"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28829" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1713 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1713" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1713" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:28.086-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.494-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28822" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer clipboard information disclosure vulnerability - CVE-2015-1692 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1692" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard contents via crafted web script, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:10.583-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.214-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28821" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-1661 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1661" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:08.311-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:22.648-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:21.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28818" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1733 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1733" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2389 and CVE-2015-2411.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:16.364-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:39.118-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:09.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28816" version="3" class="vulnerability">
      <metadata>
        <title>Registry virtualization elevation of privilege vulnerability - CVE-2015-0073 (MS15-025)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0073"/>
        <description>The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain privileges via a crafted application, aka "Registry Virtualization Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:19:02.985-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.992-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:25.548-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138397"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:137988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22943" test_ref="oval:org.mitre.oval:tst:138117"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18738" test_ref="oval:org.mitre.oval:tst:138289"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 (x86) and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21368" test_ref="oval:org.mitre.oval:tst:138325"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 (x64)/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 (x64) / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21369" test_ref="oval:org.mitre.oval:tst:138237"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.3.9600.17668" test_ref="oval:org.mitre.oval:tst:138192"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28815" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1704 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1704" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1703.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:02.152-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:27.706-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:28.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28811" version="3" class="vulnerability">
      <metadata>
        <title>OWA modified canary parameter cross site scripting vulnerability - CVE-2015-1628 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1628"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted X-OWA-Canary cookie in an AD.RecipientType.User action, aka "OWA Modified Canary Parameter Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:14.964-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.759-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:25.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28808" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1680 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1680"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1677, CVE-2015-1678, and CVE-2015-1679.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:25.622-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:27.428-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:28.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28807" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0088 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0088"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0090, CVE-2015-0091, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:58.583-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.571-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:24.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28806" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Bitmap handling use after free vulnerability - CVE-2015-1722 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1722"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Bitmap Handling Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:28.704-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:27.917-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:36.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28804" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2390 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2390" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2390" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2397, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:40.950-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:38.450-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:08.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28803" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-0077 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0077"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information from kernel memory, and possibly bypass the ASLR protection mechanism, via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:37.910-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.352-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:24.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5561" test_ref="oval:org.mitre.oval:tst:138314"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:138135"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138121"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18773" test_ref="oval:org.mitre.oval:tst:138032"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22978" test_ref="oval:org.mitre.oval:tst:138003"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28783" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1662 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1662" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1659 and CVE-2015-1665.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:12.782-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:21.122-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:20.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28781" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1626 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1626" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0056 and CVE-2015-1623.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:34.504-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:14.575-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28780" version="3" class="vulnerability">
      <metadata>
        <title>Task scheduler security feature bypass vulnerability - CVE-2015-0084 (MS15-028)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0084"/>
        <description>The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended restrictions on launching executable files via a crafted task, aka "Task Scheduler Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:28:14.673-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:14.260-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ubpm.dll is less than 6.1.7601.22948" test_ref="oval:org.mitre.oval:tst:138109"/>
              <criterion comment="Check if the version of Ubpm.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138316"/>
            </criteria>
            <criterion comment="Check if the version of Ubpm.dll is less than 6.1.7601.18741" test_ref="oval:org.mitre.oval:tst:138334"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ubpm.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:137999"/>
              <criterion comment="Check if the version of Ubpm.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138439"/>
            </criteria>
            <criterion comment="Check if the version of Ubpm.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ubpm.dll is less than 6.3.9600.17671" test_ref="oval:org.mitre.oval:tst:138035"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28771" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0092 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0092"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0091, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:45:00.714-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.976-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28770" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0090 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0090"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0091, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:53.942-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.784-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28769" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1737 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1737" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1737" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1736, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:08.182-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:26.587-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:33.026-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28768" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0056 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0056" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1623 and CVE-2015-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:32.155-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.592-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28767" version="4" class="vulnerability">
      <metadata>
        <title>Group Policy security feature bypass vulnerability - CVE-2015-0009 (MS15-014)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0009"/>
        <description>The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing requirement and trigger a revert-to-default action by spoofing domain-controller responses, aka "Group Policy Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:20:38.547-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43110 - bulletins for the month of February 2015" date="2015-02-16T13:18:00.755-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-03-09T04:01:53.352-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:29.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Scesrv.dll is less than 5.2.3790.5492" test_ref="oval:org.mitre.oval:tst:137802"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.0.6002.23558" test_ref="oval:org.mitre.oval:tst:138116"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137943"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.0.6002.19251" test_ref="oval:org.mitre.oval:tst:138132"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.1.7601.22894" test_ref="oval:org.mitre.oval:tst:137878"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137512"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.1.7601.18686" test_ref="oval:org.mitre.oval:tst:138089"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137843"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138020"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.2.9200.17200" test_ref="oval:org.mitre.oval:tst:138096"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Scesrv.dll is less than 6.3.9600.17552" test_ref="oval:org.mitre.oval:tst:137690"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28764" version="3" class="vulnerability">
      <metadata>
        <title>Windows create process elevation of privilege vulnerability - CVE-2015-0062 (MS15-015)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0062"/>
        <description>Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a process that uses the SeAssignPrimaryTokenPrivilege privilege, aka "Windows Create Process Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:22:14.916-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:53.140-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18715" test_ref="oval:org.mitre.oval:tst:137284"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22921" test_ref="oval:org.mitre.oval:tst:137701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17231" test_ref="oval:org.mitre.oval:tst:138000"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:138067"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:138065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28762" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft schannel remote code execution vulnerability - CVE-2015-0003 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0003"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:46.665-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.789-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.391-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.275-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:26.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28757" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1622 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1622" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:46.514-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.440-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28753" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1689 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1689" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1705.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:30.439-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:26.222-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:26.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28750" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0038 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0038" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0042 and CVE-2015-0046.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:31.933-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.534-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28748" version="3" class="vulnerability">
      <metadata>
        <title>ExchangeDLP cross site scripting vulnerability - CVE-2015-1629 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1629"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "ExchangeDLP Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:15.740-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.291-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28743" version="3" class="vulnerability">
      <metadata>
        <title>Win32k information disclosure vulnerability - CVE-2015-2367 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2367"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from uninitialized kernel memory via a crafted application, aka "Win32k Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:51.163-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:36.176-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:08.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28742" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1675 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1675"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:56.931-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:25.427-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:24.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28739" version="4" class="vulnerability">
      <metadata>
        <title>.NET XML decryption denial of service vulnerability - CVE-2015-1672 (MS15-048)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1672"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performance degradation) via crafted encrypted data in an XML document, aka ".NET XML Decryption Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:35:01.777-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:25.043-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:24.067-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28739 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:17.046-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criterion comment="Check if the version of System.Security.dll is less than 2.0.50727.3665" test_ref="oval:org.mitre.oval:tst:138113"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.4256" test_ref="oval:org.mitre.oval:tst:138846"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.6426" test_ref="oval:org.mitre.oval:tst:138697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138758"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.5490" test_ref="oval:org.mitre.oval:tst:138559"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.2056" test_ref="oval:org.mitre.oval:tst:138327"/>
              <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80978"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.1031" test_ref="oval:org.mitre.oval:tst:138792"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36288" test_ref="oval:org.mitre.oval:tst:138794"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check fi the version of system.security.dll is less than 4.0.30319.34252" test_ref="oval:org.mitre.oval:tst:138631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138774"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138774"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138577"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28738" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0093 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0093"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0091, and CVE-2015-0092.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:45:02.924-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.071-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28737" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0072 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:18.057-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.812-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28735" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0044 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0044" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0050.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:33.397-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.272-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28732" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0039 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0039" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0052, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:36.175-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.070-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28731" version="5" class="vulnerability">
      <metadata>
        <title>TIFF Processing information disclosure vulnerability - CVE-2015-0061 (MS15-016)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0061"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process memory via a crafted image file, aka "TIFF Processing Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:23:35.449-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.816-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28731 - fixed check for Windowscodecs.ddl version" date="2015-04-15T12:25:00.421-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2015-04-15T12:28:01.420-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:18.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdiplus.dll is less than 5.2.6002.23588" test_ref="oval:org.mitre.oval:tst:137169"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135896"/>
              <criterion comment="Check if the version Windowscodecs.dll of is less than 7.0.6002.23591" test_ref="oval:org.mitre.oval:tst:138070"/>
            </criteria>
            <criterion comment="Check if the version Windowscodecs.dll of is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138090"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Windowscodecs.dll is 6.1 or 6.2">
            <criteria comment="6.2">
              <criterion comment="Check if the version Windowscodecs.dll of is greater than 6.2" test_ref="oval:org.mitre.oval:tst:137662"/>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
                  <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137952"/>
                </criteria>
                <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:137222"/>
              </criteria>
            </criteria>
            <criteria comment="6.1">
              <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2" test_ref="oval:org.mitre.oval:tst:138040"/>
              <criteria operator="OR" comment="either file versions">
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.22922" test_ref="oval:org.mitre.oval:tst:138081"/>
                  <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137874"/>
                </criteria>
                <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.18716" test_ref="oval:org.mitre.oval:tst:137954"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
              <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.21345" test_ref="oval:org.mitre.oval:tst:138119"/>
            </criteria>
            <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.17228" test_ref="oval:org.mitre.oval:tst:137975"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version Windowscodecs.dll of is less than 6.3.9600.17631" test_ref="oval:org.mitre.oval:tst:137585"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28730" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver denial of service vulnerability - CVE-2015-0074 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0074"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted (1) web site or (2) file, aka "Adobe Font Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:46.568-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.601-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28728" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0055 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0055" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:43.195-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.473-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28724" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1754 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-1754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1754" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:02.186-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:23.768-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:29.710-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28718" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0022 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0022" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:07.271-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.071-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.532-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28717" version="3" class="vulnerability">
      <metadata>
        <title>Directory Traversal elevation of privilege vulnerability - CVE-2015-0016 (MS15-004)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Windows Remote Desktop Connection 7.0</product>
          <product>Microsoft Windows Remote Desktop Connection 8.0</product>
          <product>Microsoft Windows Remote Desktop Connection 8.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0016"/>
        <description>Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:19:16.598-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:37.791-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:33.966-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / Remote Desktop 7.0 / vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Remote Desktop 7.0 and Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7600.17715" test_ref="oval:org.mitre.oval:tst:137087"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7600.00000" test_ref="oval:org.mitre.oval:tst:136870"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7600.21000" test_ref="oval:org.mitre.oval:tst:137555"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7600.21909" test_ref="oval:org.mitre.oval:tst:137523"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.18699" test_ref="oval:org.mitre.oval:tst:137471"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137404"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.22907" test_ref="oval:org.mitre.oval:tst:137490"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.0 and vulnerable version">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.17212" test_ref="oval:org.mitre.oval:tst:137630"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:137557"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.0 and Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:136901"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.21329" test_ref="oval:org.mitre.oval:tst:136668"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.1 and vulnerable version">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.3.9600.17553" test_ref="oval:org.mitre.oval:tst:136858"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.3.9600.00000" test_ref="oval:org.mitre.oval:tst:137545"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2008 R2 IA64 + vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.18699" test_ref="oval:org.mitre.oval:tst:137471"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137404"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.22907" test_ref="oval:org.mitre.oval:tst:137490"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.17213" test_ref="oval:org.mitre.oval:tst:137622"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:136901"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.21329" test_ref="oval:org.mitre.oval:tst:136668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Tswbprxy.exe is less than 6.3.9600.17555" test_ref="oval:org.mitre.oval:tst:137058"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28714" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0025 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0025" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0023.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:11.825-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.861-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <criteria operator="AND" comment="Win 7/R2">
            <criteria operator="OR" comment="Win 7/R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8/ 2012 R2">
            <criteria operator="OR" comment="Win 8/ 2012">
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28711" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0020 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0020" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:08.991-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.416-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28710" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1696 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1696"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:52.133-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:24.609-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:23.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28709" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1665 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1665" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1665" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1659 and CVE-2015-1662.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:02.972-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:18.790-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:19.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28708" version="3" class="vulnerability">
      <metadata>
        <title>Graphics component EOP vulnerability - CVE-2015-2364 (MS15-072)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2364"/>
        <description>The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that leverages an incorrect bitmap conversion, aka "Graphics Component EOP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T20:35:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:24:06.820-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:35.282-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:07.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 vulnerable version">
          <criteria operator="OR" comment="Server (2003 - x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdi32.dll is less than 5.2.3790.5661" test_ref="oval:org.mitre.oval:tst:140966"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.19421" test_ref="oval:org.mitre.oval:tst:141236"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87308"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.23728" test_ref="oval:org.mitre.oval:tst:140635"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.18898" test_ref="oval:org.mitre.oval:tst:141266"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:87215"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.23100" test_ref="oval:org.mitre.oval:tst:141108"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.2.9200.17410" test_ref="oval:org.mitre.oval:tst:141167"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of gdi32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114810"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.2.9200.21521" test_ref="oval:org.mitre.oval:tst:141249"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of gdi32.dll is less than 6.3.9600.17902" test_ref="oval:org.mitre.oval:tst:141114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28704" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1657 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1657" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:22.070-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:18.550-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:19.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28700" version="3" class="vulnerability">
      <metadata>
        <title>Group Policy remote code execution vulnerability - CVE-2015-0008 (MS15-011)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0008"/>
        <description>The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:15:28.177-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.064-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.706-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable version">
          <criteria operator="OR" comment="Vista (x86/x64) / 2k8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:137915"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Gpsvc.dll is less than 6.1.7601.22917" test_ref="oval:org.mitre.oval:tst:137883"/>
              <criterion comment="Check if the version of Gpsvc.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137655"/>
            </criteria>
            <criterion comment="Check if the version of Gpsvc.dll is less than 6.1.7601.18711" test_ref="oval:org.mitre.oval:tst:137989"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Gpsvc.dll is less than 6.2.9200.21339" test_ref="oval:org.mitre.oval:tst:137798"/>
              <criterion comment="Check if the version of Gpsvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137613"/>
            </criteria>
            <criterion comment="Check if the version of Gpsvc.dll is less than 6.2.9200.17225" test_ref="oval:org.mitre.oval:tst:137951"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Gpsvc.dll is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:138043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28695" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0049 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0049" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:10:54.028-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.793-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28694" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: WTS remote code execution vulnerability - CVE-2015-0081 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0081"/>
        <description>Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:40:13.969-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.328-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.040-04:00">ACCEPTED</status_change>
            <modified comment="Duplicate of 27987" date="2015-05-06T14:09:19.017-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2015-05-06T14:09:19.017-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msctf.dll is less than 5.2.3790.5528" test_ref="oval:org.mitre.oval:tst:138239"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.19296" test_ref="oval:org.mitre.oval:tst:138034"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138111"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.23606" test_ref="oval:org.mitre.oval:tst:137872"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.18731" test_ref="oval:org.mitre.oval:tst:138101"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138359"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.22937" test_ref="oval:org.mitre.oval:tst:138352"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.17243" test_ref="oval:org.mitre.oval:tst:138103"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138024"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.21361" test_ref="oval:org.mitre.oval:tst:138146"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version msctf.dll is less than 6.3.9600.17664" test_ref="oval:org.mitre.oval:tst:138158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28692" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1703 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1703" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1703" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1704.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:27.260-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:23.965-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:22.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28691" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0045 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0045" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0053.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:35.064-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.533-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.264-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28689" version="5" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-0057 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0057"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:48.608-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.214-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.910-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.638-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:23.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28688" version="5" class="vulnerability">
      <metadata>
        <title>Windows font driver denial of service vulnerability - CVE-2015-0060 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0060"/>
        <description>The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Windows Font Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:51.771-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.917-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.858-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:23.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28684" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0091 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0091"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:51.497-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.060-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:20.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28683" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0052 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0052" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0039, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:29.508-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.699-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28680" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1714 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1714" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1714" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:18.628-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:22.964-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:21.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28675" version="3" class="vulnerability">
      <metadata>
        <title>JPEG XR parser information disclosure vulnerability - CVE-2015-0076 (MS15-029)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0076"/>
        <description>The photo-decoder implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly initialize memory for rendering of JXR images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "JPEG XR Parser Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:32:06.528-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.733-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:20.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 7.0.6002.19299" test_ref="oval:org.mitre.oval:tst:137741"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138411"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 7.0.6002.23609" test_ref="oval:org.mitre.oval:tst:138249"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.18742" test_ref="oval:org.mitre.oval:tst:138361"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138077"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.22949" test_ref="oval:org.mitre.oval:tst:137949"/>
            </criteria>
            <criteria operator="AND" comment="Wmphoto.dll with version range 6.2.9200.xxxx">
              <criteria operator="OR" comment="gdr/ldr">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.21371" test_ref="oval:org.mitre.oval:tst:137649"/>
                  <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138341"/>
                </criteria>
                <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.17254" test_ref="oval:org.mitre.oval:tst:137935"/>
              </criteria>
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:138413"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Server 2008 R2 IA64 + vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.18742" test_ref="oval:org.mitre.oval:tst:138361"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138077"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.22949" test_ref="oval:org.mitre.oval:tst:137949"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138074"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137881"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:138010"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Wmphoto.dll is less than 6.3.9600.17668" test_ref="oval:org.mitre.oval:tst:138258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28672" version="3" class="vulnerability">
      <metadata>
        <title>Schannel information disclosure vulnerability - CVE-2015-1716 (MS15-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1716" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1716"/>
        <description>Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict Diffie-Hellman Ephemeral (DHE) key lengths, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, aka "Schannel Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:55:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:54:28.486-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:22.618-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:21.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          </criteria>
          <criterion comment="Check if the version of schannel.dll is less than 5.2.3790.5618" test_ref="oval:org.mitre.oval:tst:138556"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of schannel.dll is less than 6.0.6002.19375" test_ref="oval:org.mitre.oval:tst:138676"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:134478"/>
              <criterion comment="Check if the version of schannel.dll is less than 6.0.6002.23683" test_ref="oval:org.mitre.oval:tst:138299"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of schannel.dll is less than 6.1.7601.18843" test_ref="oval:org.mitre.oval:tst:138711"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of schannel.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135418"/>
              <criterion comment="Check if the version of schannel.dll is less than 6.1.7601.23045" test_ref="oval:org.mitre.oval:tst:138601"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of schannel.dll is less than 6.2.9200.17361" test_ref="oval:org.mitre.oval:tst:138783"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135406"/>
              <criterion comment="Check if the version of schannel.dll is less than 6.2.9200.21473" test_ref="oval:org.mitre.oval:tst:138718"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of schannel.dll is less than 6.3.9600.17810" test_ref="oval:org.mitre.oval:tst:138388"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28670" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1623 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1623" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1623" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0056 and CVE-2015-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:35.680-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.600-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:20.006-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28667" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-0095 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0095"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service (NULL pointer dereference and blue screen), or obtain sensitive information from kernel memory and possibly bypass the ASLR protection mechanism, via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:40.719-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.294-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:19.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5561" test_ref="oval:org.mitre.oval:tst:138314"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:138135"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138121"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18773" test_ref="oval:org.mitre.oval:tst:138032"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22978" test_ref="oval:org.mitre.oval:tst:138003"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28666" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability  - CVE-2015-0019 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0019" source="CVE"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:38.283-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.274-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:23.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28665" version="3" class="vulnerability">
      <metadata>
        <title>Win32k buffer overflow vulnerability - CVE-2015-1725 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1725"/>
        <description>Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:23.931-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:20.626-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:25.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28664" version="3" class="vulnerability">
      <metadata>
        <title>Graphics component information disclosure vulnerability - CVE-2015-0002 (MS15-001)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0002"/>
        <description>The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gain privileges by running AppCompatCache.exe with a crafted DLL file, aka MSRC ID 20544 or "Microsoft Application Compatibility Infrastructure Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T11:10:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:04:43.938-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:36.479-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:32.500-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18700" test_ref="oval:org.mitre.oval:tst:136995"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22908" test_ref="oval:org.mitre.oval:tst:137258"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17214" test_ref="oval:org.mitre.oval:tst:137534"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137475"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17213" test_ref="oval:org.mitre.oval:tst:137528"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137475"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ahcache.sys is less than 6.3.9600.17555" test_ref="oval:org.mitre.oval:tst:137524"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28663" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0066 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0066" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0066" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0037, and CVE-2015-0040.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:03.642-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.114-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:23.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="either file">
              <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28658" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint xss vulnerability – CVE-2015-1636 (MS15-022)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1636" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1636"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T17:47:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T09:59:52.885-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.162-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:19.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.611-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:22.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint Foundation Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138170"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138254"/>
            <criterion comment="Check if the version of wwintl.dll is less than 15.0.4631.1000" test_ref="oval:org.mitre.oval:tst:138441"/>
            <criterion comment="Check if the version of vutils.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138393"/>
            <criterion comment="Check if the version of microsoft.office.infopath.server.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138339"/>
            <criterion comment="Check if the version of ascalc.dll is less than 15.0.4699.1000" test_ref="oval:org.mitre.oval:tst:138351"/>
            <criterion comment="Check if the version of msoserverintl.dll is less than 15.0.4697.1000" test_ref="oval:org.mitre.oval:tst:138449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28656" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-0094 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0094"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the availability of address information during a function call, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:35.174-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:10.869-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:18.878-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5561" test_ref="oval:org.mitre.oval:tst:138314"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:138135"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138121"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18773" test_ref="oval:org.mitre.oval:tst:138032"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22978" test_ref="oval:org.mitre.oval:tst:138003"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28653" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0031 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0031" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:05.422-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:47.712-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:23.031-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28650" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1741 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1741" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1752.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:10.880-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:20.163-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:25.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28649" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1698 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1698"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:55.364-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:21.993-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:19.783-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28641" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1688 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1688" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:14.393-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:21.161-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:18.368-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28639" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0040 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0040" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0040" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0037, and CVE-2015-0066.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:04.359-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:47.516-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:22.552-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="either file">
              <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28633" version="5" class="vulnerability">
      <metadata>
        <title>TrueType font parsing remote code execution vulnerability - CVE-2015-0059 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0059"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:49.822-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:47.127-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:22.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:10.104-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:20.800-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28624" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: DLL planting remote code execution vulnerability - CVE-2015-0096 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0096"/>
        <description>Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading during Windows Explorer access to the icon of a crafted shortcut, aka "DLL Planting Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:40:17.798-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:10.178-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:17.952-04:00">ACCEPTED</status_change>
            <modified comment="Duplicate of def:28609" date="2015-05-06T14:06:09.994-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2015-05-06T14:06:09.994-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.0.3790.5558" test_ref="oval:org.mitre.oval:tst:138302"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.19322" test_ref="oval:org.mitre.oval:tst:138377"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113981"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.23632" test_ref="oval:org.mitre.oval:tst:138023"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.18762" test_ref="oval:org.mitre.oval:tst:138303"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113444"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.22969" test_ref="oval:org.mitre.oval:tst:138272"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.17279" test_ref="oval:org.mitre.oval:tst:138140"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137937"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.21395" test_ref="oval:org.mitre.oval:tst:138060"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.3.9600.17680" test_ref="oval:org.mitre.oval:tst:138190"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28623" version="3" class="vulnerability">
      <metadata>
        <title>HTTP.sys Remote code execution vulnerability - CVE-2015-1635 (MS15-034)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1635" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1635"/>
        <description>HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T14:55:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:14:50.653-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:17.227-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:18.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of http.sys is less than 6.1.7601.22976" test_ref="oval:org.mitre.oval:tst:138500"/>
              <criterion comment="Check if the version of http.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138391"/>
            </criteria>
            <criterion comment="Check if the version of http.sys is less than 6.1.7601.18772" test_ref="oval:org.mitre.oval:tst:138381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of http.sys is less than 6.2.9200.21401" test_ref="oval:org.mitre.oval:tst:138499"/>
              <criterion comment="Check if the version of http.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137708"/>
            </criteria>
            <criterion comment="Check if the version of http.sys is less than 6.2.9200.17285" test_ref="oval:org.mitre.oval:tst:138346"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of http.sys is less than 6.3.9600.17712" test_ref="oval:org.mitre.oval:tst:138014"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28614" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2384 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2384" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2425.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:35.092-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:34.947-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:06.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28610" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1730 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1730" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:06.972-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:17.996-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:22.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28609" version="3" class="vulnerability">
      <metadata>
        <title>DLL planting remote code execution vulnerability - CVE-2015-0096 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0096"/>
        <description>Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading during Windows Explorer access to the icon of a crafted shortcut, aka "DLL Planting Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:49:20.296-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:09.924-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:17.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.0.3790.5558" test_ref="oval:org.mitre.oval:tst:137978"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.19322" test_ref="oval:org.mitre.oval:tst:137997"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113981"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.23632" test_ref="oval:org.mitre.oval:tst:138386"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.18762" test_ref="oval:org.mitre.oval:tst:138107"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113444"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.22969" test_ref="oval:org.mitre.oval:tst:138138"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.17279" test_ref="oval:org.mitre.oval:tst:138337"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138161"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.21395" test_ref="oval:org.mitre.oval:tst:138265"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.3.9600.17680" test_ref="oval:org.mitre.oval:tst:138266"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28607" version="3" class="vulnerability">
      <metadata>
        <title>Exchange Server-Side Request Forgery vulnerability - CVE-2015-1764 (MS15-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1764"/>
        <description>The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origin Policy and send HTTP traffic to intranet servers via a crafted request, related to a Server-Side Request Forgery (SSRF) issue, aka "Exchange Server-Side Request Forgery Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:51.904-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:11.617-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:49.943-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.41" test_ref="oval:org.mitre.oval:tst:139078"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU8 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 8 is installed" definition_ref="oval:org.mitre.oval:def:29138"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1076.011" test_ref="oval:org.mitre.oval:tst:139030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29138" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 Cumulative Update 8 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu8"/>
        <description>Microsoft Exchange Server 2013 Cumulative Update 8 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T18:41:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:51.193-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:18.099-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:53.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 Cumulative Update 8 is installed" test_ref="oval:org.mitre.oval:tst:138824"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28605" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1627 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1627" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1627" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:41.386-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:09.609-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:17.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21443" test_ref="oval:org.mitre.oval:tst:137862"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19310" test_ref="oval:org.mitre.oval:tst:138155"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23620" test_ref="oval:org.mitre.oval:tst:138114"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28603" version="3" class="vulnerability">
      <metadata>
        <title>Windows MS-DOS device name vulnerability - CVE-2015-1644 (MS15-038)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1644" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1644"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows MS-DOS Device Name Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T09:23:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:20:32.765-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:16.667-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:18.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003(x86/x64) and vulnerable file versions">
          <criteria operator="OR" comment="Server 2003 (x86/x64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Check if the version of ntoskrnl.exe is less than 5.2.3790.5583" test_ref="oval:org.mitre.oval:tst:138376"/>
        </criteria>
        <criteria operator="AND" comment="Server 2003 IA64 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          <criterion comment="Check if the version of Ntkrnlmp.exe is less than 5.2.3790.5583" test_ref="oval:org.mitre.oval:tst:138097"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of ntoskrnl.exe is less than 6.0.6002.19346" test_ref="oval:org.mitre.oval:tst:138013"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of ntoskrnl.exe is less than 6.0.6002.23654" test_ref="oval:org.mitre.oval:tst:138515"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of ntoskrnl.exe is less than 6.1.7601.18798" test_ref="oval:org.mitre.oval:tst:137967"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of ntoskrnl.exe is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138152"/>
              <criterion comment="Check if the version of ntoskrnl.exe is less than 6.1.7601.23002" test_ref="oval:org.mitre.oval:tst:138528"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of ntoskrnl.exe is less than 6.2.9200.17313" test_ref="oval:org.mitre.oval:tst:138572"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of ntoskrnl.exe is less than 6.2.9200.21428" test_ref="oval:org.mitre.oval:tst:138550"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/Server 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of ntoskrnl.exe is less than 6.3.9600.17736" test_ref="oval:org.mitre.oval:tst:138069"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28593" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1750 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1750" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1750" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1742, CVE-2015-1747, and CVE-2015-1753.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:41.275-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:17.821-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:22.017-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28590" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0048 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0048" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0028.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:22.486-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:46.252-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:21.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
          </criteria>
          <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
          <criteria operator="AND" comment="Jscript and LDR">
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
            <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28576" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1694 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1694" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1710.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:15:58.611-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:19.406-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:17.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28574" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1659 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1659" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1662 and CVE-2015-1665.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:23.185-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:16.357-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:18.169-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28573" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0043 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0043" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:00.683-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:45.664-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:20.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28569" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1634 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1634" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1634" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1625.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:24.225-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:09.295-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:16.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5543" test_ref="oval:org.mitre.oval:tst:138082"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21443" test_ref="oval:org.mitre.oval:tst:137862"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19310" test_ref="oval:org.mitre.oval:tst:138155"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23620" test_ref="oval:org.mitre.oval:tst:138114"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28562" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft Schannel could allow security feature bypass - CVE-2015-1637 (MS15-031)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1637" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1637"/>
        <description>Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204 and CVE-2015-1067.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T10:05:02.556-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.997-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:16.285-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Schannel.dll is less than 5.2.3790.5564" test_ref="oval:org.mitre.oval:tst:138366"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:134478"/>
              <criterion comment="Check if the version of Schannel.dll is less than 6.0.6002.23640" test_ref="oval:org.mitre.oval:tst:138169"/>
            </criteria>
            <criterion comment="Check if the version of Schannel.dll is less than 6.0.6002.19332" test_ref="oval:org.mitre.oval:tst:137934"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of schannel.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135418"/>
              <criterion comment="Check if the version of Schannel.dll is less than 6.1.7601.22983" test_ref="oval:org.mitre.oval:tst:137769"/>
            </criteria>
            <criterion comment="Check if the version of Schannel.dll is less than 6.1.7601.18779" test_ref="oval:org.mitre.oval:tst:138168"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135406"/>
              <criterion comment="Check if the version of Schannel.dll is less than 6.2.9200.21410" test_ref="oval:org.mitre.oval:tst:138230"/>
            </criteria>
            <criterion comment="Check if the version of Schannel.dll is less than 6.2.9200.17293" test_ref="oval:org.mitre.oval:tst:138298"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Schannel.dll is less than 6.3.9600.17702" test_ref="oval:org.mitre.oval:tst:138186"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28558" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0026 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0026" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:10:58.146-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:45.343-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:20.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28555" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1679 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1679"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1677, CVE-2015-1678, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:27.606-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:18.464-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:16.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28554" version="6" class="vulnerability">
      <metadata>
        <title>Windows Telnet service buffer overflow vulnerability - CVE-2015-0014 (MS15-002)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0014"/>
        <description>Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows Telnet Service Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:08:23.374-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:30.935-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43110 - bulletins for the month of February 2015" date="2015-02-16T13:18:00.755-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-03-09T04:01:45.127-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:137241 - obj:43110 checks scesrv.dll but should check tlntsess.exe. New object checks correct filename." date="2015-03-24T12:05:00.907-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-24T12:07:29.845-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:18.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Tlntsess.exe is less than 5.2.3790.5491" test_ref="oval:org.mitre.oval:tst:137350"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Tlntsess.exe is less than 6.0.6002.23557" test_ref="oval:org.mitre.oval:tst:136633"/>
              <criterion comment="Check if the version of Tlntsess.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:136835"/>
            </criteria>
            <criterion comment="Check if the version of Tlntsess.exe is less than 6.0.6002.19250" test_ref="oval:org.mitre.oval:tst:137168"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Tlntsess.exe is less than 6.1.7601.22893" test_ref="oval:org.mitre.oval:tst:137549"/>
              <criterion comment="Check if the version of Tlntsess.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137241"/>
            </criteria>
            <criterion comment="Check if the version of Tlntsess.exe is less than 6.1.7601.18685" test_ref="oval:org.mitre.oval:tst:137409"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Tlntsess.exe is less than 6.2.9200.21315" test_ref="oval:org.mitre.oval:tst:137104"/>
              <criterion comment="Check if the version of Tlntsess.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137303"/>
            </criteria>
            <criterion comment="Check if the version of Tlntsess.exe is less than 6.2.9200.17198" test_ref="oval:org.mitre.oval:tst:137527"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Tlntsess.exe is less than 6.3.9600.17547" test_ref="oval:org.mitre.oval:tst:137521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28549" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver information disclosure vulnerability - CVE-2015-0089 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0089"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted font, aka "Adobe Font Driver Information Disclosure Vulnerability," a different vulnerability than CVE-2015-0087.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:56.363-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.779-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:15.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28548" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer use-after-free vulnerability - CVE-2014-8967 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2014-8967" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8967" source="CVE"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted HTML document in conjunction with a Cascading Style Sheets (CSS) token sequence specifying the run-in value for the display property, leading to improper CElement reference counting.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:55.078-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:44.788-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:19.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28540" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0021 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0021" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:09.943-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:44.434-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:19.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28530" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1731 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1731" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1736, CVE-2015-1737, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:17.220-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:15.745-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:20.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28529" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2401 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2401" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2401" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:20.056-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:33.970-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:04.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28525" version="3" class="vulnerability">
      <metadata>
        <title>Windows LoadLibrary EoP vulnerability - CVE-2015-1758 (MS15-063)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1758"/>
        <description>Untrusted search path vulnerability in the LoadLibrary function in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a Trojan horse DLL in an unspecified directory, aka "Windows LoadLibrary EoP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T00:37:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:09:02.047-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:10.021-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:48.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.19381" test_ref="oval:org.mitre.oval:tst:139077"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113560"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.23688" test_ref="oval:org.mitre.oval:tst:139079"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 SP1 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.18847" test_ref="oval:org.mitre.oval:tst:138212"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113836"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.23049" test_ref="oval:org.mitre.oval:tst:138094"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of kernelbase.dll is less than 6.2.9200.17366" test_ref="oval:org.mitre.oval:tst:139013"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of kernelbase.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:138812"/>
              <criterion comment="Check if the version of kernelbase.dll is less than 6.2.9200.21478" test_ref="oval:org.mitre.oval:tst:138822"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28524" version="3" class="vulnerability">
      <metadata>
        <title>Audit report cross site scripting vulnerability - CVE-2015-1630 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1630"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Audit Report Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:14.215-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.617-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:15.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28523" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint XSS vulnerability – CVE-2015-1653 (MS15-036)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1653" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1653"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:26:54.953-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:14.929-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:17.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if the version of Microsoft.Office.Server.Search.dll is less than 15.0.4711.1000" test_ref="oval:org.mitre.oval:tst:137998"/>
        <criteria operator="OR" comment="Either SharePoint Server 2013 / SharePoint Foundation 2013">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28522" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0046 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0046" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0038 and CVE-2015-0042.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:10.809-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:44.035-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:18.977-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28518" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1745 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1745" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:38.870-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:15.409-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:19.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28517" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1695 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1695" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1695"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1696, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:53.501-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:17.873-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:15.156-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28512" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1752 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1752" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1741.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:22.424-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:14.532-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:17.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28487" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1625 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1625" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1634.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:44.815-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.014-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:15.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5543" test_ref="oval:org.mitre.oval:tst:138082"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21443" test_ref="oval:org.mitre.oval:tst:137862"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19310" test_ref="oval:org.mitre.oval:tst:138155"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23620" test_ref="oval:org.mitre.oval:tst:138114"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28486" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-0051 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-0051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0051" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:44.709-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:43.254-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:18.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28478" version="3" class="vulnerability">
      <metadata>
        <title>Network policy server RADIUS implementation denial of service vulnerability - CVE-2015-0015 (MS15-007)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0015"/>
        <description>Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Network Policy Server (NPS), aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:29:46.815-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:24.994-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:22.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Iassam.dll is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137699"/>
        </criteria>
        <criteria operator="AND" comment="2k8 + vulnerable file version">
          <criteria operator="OR" comment="2K8">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Iassam.dll is less than 6.0.6002.23557" test_ref="oval:org.mitre.oval:tst:137566"/>
              <criterion comment="Check if the version of Iassam.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137623"/>
            </criteria>
            <criterion comment="Check if the version of Iassam.dll is less than 6.0.6002.19250" test_ref="oval:org.mitre.oval:tst:137576"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2008 R2 + vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Iassam.dll is less than 6.1.7601.22893" test_ref="oval:org.mitre.oval:tst:137139"/>
              <criterion comment="Check if the version of Iassam.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:136865"/>
            </criteria>
            <criterion comment="Check if the version of Iassam.dll is less than 6.1.7601.18685" test_ref="oval:org.mitre.oval:tst:137723"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Iassam.dll is less than 6.2.9200.21316" test_ref="oval:org.mitre.oval:tst:137648"/>
              <criterion comment="Check if the version of Iassam.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137587"/>
            </criteria>
            <criterion comment="Check if the version of Iassam.dll is less than 6.2.9200.17199" test_ref="oval:org.mitre.oval:tst:137652"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K12 R2and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          <criterion comment="Check if the version of Iassam.dll is less than 6.3.9600.17549" test_ref="oval:org.mitre.oval:tst:137501"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28475" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0035 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0035" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:13.068-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:43.016-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:18.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28473" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1708 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1708" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1708" source="CVE"/>
        <description>Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:20.044-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:17.265-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:13.790-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28469" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver information disclosure vulnerability - CVE-2015-0087 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0087"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted font, aka "Adobe Font Driver Information Disclosure Vulnerability," a different vulnerability than CVE-2015-0089.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:48.840-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:07.774-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:14.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28464" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0099 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0099" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:33.444-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:07.539-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:14.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28449" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-0069 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0069" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:46.039-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:41.636-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:17.949-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28429" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer information disclosure vulnerability - CVE-2015-1765 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1765" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to read the browser history via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:40.483-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:12.948-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:15.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28428" version="3" class="vulnerability">
      <metadata>
        <title>Malformed PNG parsing information disclosure vulnerability - CVE-2015-0080 (MS15-024)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0080"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Malformed PNG Parsing Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:15:02.927-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:06.923-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:13.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdiplus.dll is less than 5.2.6002.23609" test_ref="oval:org.mitre.oval:tst:138297"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135896"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 7.0.6002.23609" test_ref="oval:org.mitre.oval:tst:137953"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 7.0.6002.19299" test_ref="oval:org.mitre.oval:tst:138197"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.21369" test_ref="oval:org.mitre.oval:tst:137896"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.22948" test_ref="oval:org.mitre.oval:tst:138144"/>
              <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137874"/>
            </criteria>
            <criteria operator="AND" comment="range to avoid FP">
              <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:138207"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138224"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.18741" test_ref="oval:org.mitre.oval:tst:137778"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows 2008 R2 IA64">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.22948" test_ref="oval:org.mitre.oval:tst:138144"/>
              <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137874"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.18741" test_ref="oval:org.mitre.oval:tst:137778"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.21369" test_ref="oval:org.mitre.oval:tst:137896"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138224"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Windowscodecs.dll is less than 6.3.9600.17669" test_ref="oval:org.mitre.oval:tst:138402"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28425" version="3" class="vulnerability">
      <metadata>
        <title>Outlook Web App token spoofing vulnerability (CVE-2014-6319) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6319"/>
        <description>Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:20.948-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.958-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:43.811-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 (no Service Pack) is installed" definition_ref="oval:org.mitre.oval:def:1641"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.03.0389.002" test_ref="oval:org.mitre.oval:tst:135507"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:15107"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.03.0224.001" test_ref="oval:org.mitre.oval:tst:135743"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1641" version="5" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2007 (no Service Pack) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2007:gold"/>
        <description>Exchange Server 2007 (no Service Pack) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:34.310-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:35.112-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.621-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:51:06.842-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:00.696-05:00">ACCEPTED</status_change>
            <modified comment="The method it was using to check for lack of a service pack is not valid for Exchange 2007." date="2008-07-11T11:14:00.045-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2008-07-11T11:18:44.060-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:05.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1641 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:54.126-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:33.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Exchange Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:8521"/>
        <criterion comment="No Exchange Server 2007 SP is installed." test_ref="oval:org.mitre.oval:tst:8498"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15107" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange:2010"/>
        <description>Microsoft Exchange Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-04-04T12:52:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2012-04-06T11:34:21.490-04:00">DRAFT</status_change>
            <status_change date="2012-04-23T04:00:13.600-04:00">INTERIM</status_change>
            <status_change date="2012-05-14T04:00:06.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Exchange Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:77602"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28416" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6329 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6329" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6329" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6327 and CVE-2014-6376.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:59.721-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.471-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:43.109-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28415" version="3" class="vulnerability">
      <metadata>
        <title>Exchange URL redirection vulnerability (CVE-2014-6336) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6336" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6336"/>
        <description>Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:17.070-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.340-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:42.997-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28413" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0036 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0036" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0036" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:20.496-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:40.043-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:17.603-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28408" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6375 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2014-6375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6375" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:39.887-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:39.464-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:42.147-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28405" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1710 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1710" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1694.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:33.151-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:16.775-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:12.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28404" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6327 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6327" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6327" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6329 and CVE-2014-6376.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:10:07.676-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:39.318-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:41.999-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28402" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0037 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0037" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0040, and CVE-2015-0066.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:36.869-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:39.814-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:17.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="either file">
              <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28401" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6374 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-6374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6374" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:53.859-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.903-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:41.500-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5467" test_ref="oval:org.mitre.oval:tst:135844"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21420" test_ref="oval:org.mitre.oval:tst:135838"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19221" test_ref="oval:org.mitre.oval:tst:135689"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23528" test_ref="oval:org.mitre.oval:tst:135126"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28395" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0023 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0023" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0025.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:28.319-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:39.658-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:17.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <criteria operator="AND" comment="Win 7/R2">
            <criteria operator="OR" comment="Win 7/R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8/ 2012 R2">
            <criteria operator="OR" comment="Win 8/ 2012">
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28394" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0028 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0028" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0048.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:15.836-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:39.488-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:16.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
          </criteria>
          <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
          <criteria operator="AND" comment="Jscript and LDR">
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
            <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28392" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6373 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2014-6373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6373" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:10:03.090-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.608-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:41.183-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28390" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1697 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1697" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1697"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1696, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:50.726-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:16.394-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:11.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28384" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0018 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0018" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0037, CVE-2015-0040, and CVE-2015-0066.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:30.287-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:39.336-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:16.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="either file">
              <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28383" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0030 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0030" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:51.951-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:38.664-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:16.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28382" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0053 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0053" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0045.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:27.343-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:38.121-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:15.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28377" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6376 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6376" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6327 and CVE-2014-6329.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:10:00.654-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.006-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:40.508-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28376" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6368 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6368" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:10:04.174-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:37.888-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:40.370-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28368" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6363 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VBScript 5.8</product>
          <product>VBScript 5.6</product>
          <product>VBScript 5.7</product>
        </affected>
        <reference ref_id="CVE-2014-6363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6363" source="CVE"/>
        <description>vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:44.662-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:35.622-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:38.727-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:115 - pattern match update for IE 7 inventory def (replaced the greedy pattern" date="2015-02-16T13:23:00.322-05:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2015-02-16T13:25:04.800-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:37.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <criterion comment="vbscript.dll 5.6 or later is installed" test_ref="oval:org.mitre.oval:tst:100534"/>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of vbscript.dll is less than 5.6.0.8853" test_ref="oval:org.mitre.oval:tst:135632"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <criterion comment="Vbscript.dll 5.7 or later is installed" test_ref="oval:org.mitre.oval:tst:11558"/>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.23528" test_ref="oval:org.mitre.oval:tst:135236"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.19221" test_ref="oval:org.mitre.oval:tst:135777"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.23528" test_ref="oval:org.mitre.oval:tst:135236"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="IE 6/7">
            <criterion comment="Internet Explorer 7 is installed" test_ref="oval:org.mitre.oval:tst:178"/>
            <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
          <criterion comment="Vbscript.dll 5.8 or later is installed" test_ref="oval:org.mitre.oval:tst:11329"/>
          <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
            <criteria operator="AND" comment=" /2k3 and vulnerable version">
              <criteria operator="OR" comment="/ 2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23642" test_ref="oval:org.mitre.oval:tst:135324"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19587" test_ref="oval:org.mitre.oval:tst:135764"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23642" test_ref="oval:org.mitre.oval:tst:135324"/>
                  <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="vulnerable file version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18648" test_ref="oval:org.mitre.oval:tst:134997"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.22856" test_ref="oval:org.mitre.oval:tst:135690"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal 5.8.7601.22000" test_ref="oval:org.mitre.oval:tst:113859"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <criterion comment="Vbscript.dll 5.8 or later is installed" test_ref="oval:org.mitre.oval:tst:11329"/>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 8 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17104" test_ref="oval:org.mitre.oval:tst:135537"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20716" test_ref="oval:org.mitre.oval:tst:135655"/>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 9 is installed" test_ref="oval:org.mitre.oval:tst:42359"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <criterion comment="Check if Microsoft Internet Explorer 10 is installed" test_ref="oval:org.mitre.oval:tst:80429"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17183" test_ref="oval:org.mitre.oval:tst:135745"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21299" test_ref="oval:org.mitre.oval:tst:135669"/>
                    </criteria>
                  </criteria>
                </criteria>
                <criteria operator="AND" comment="Win 8 / 2012 and vulnerable file version">
                  <criteria operator="OR" comment="Win 8 / 2k12">
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of jscript.dll is less than 5.8.9200.17183" test_ref="oval:org.mitre.oval:tst:135549"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of jscript.dll is less than 5.8.9200.21299" test_ref="oval:org.mitre.oval:tst:134918"/>
                      <criterion comment="Check if the version of jscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135737"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17496" test_ref="oval:org.mitre.oval:tst:135651"/>
              <criterion comment="Check if Microsoft Internet Explorer 11 is installed" test_ref="oval:org.mitre.oval:tst:87142"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28358" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6343 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6343" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6343" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:14.494-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:04.111-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:47.178-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:11.959-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:17.556-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28349" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-8966 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2014-8966" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8966" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:10:06.501-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:34.026-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:37.102-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5467" test_ref="oval:org.mitre.oval:tst:135844"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21420" test_ref="oval:org.mitre.oval:tst:135838"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19221" test_ref="oval:org.mitre.oval:tst:135689"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23528" test_ref="oval:org.mitre.oval:tst:135126"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28347" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0027 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0027" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0035, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:16.996-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:35.895-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:15.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28340" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1691 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1691" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1712.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:03.620-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:15.453-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:10.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28339" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability. - CVE-2014-6340 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-6340" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6340" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:09.697-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.801-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:46.417-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.081-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:16.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28337" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0017 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0017" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:59.971-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:35.385-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:14.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28334" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Clipboard Information Disclosure Vulnerability - CVE-2014-6323 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference ref_id="CVE-2014-6323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6323" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:12.533-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.514-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:45.828-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.242-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:16.644-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 )">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28330" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft user profile service elevation of privilege vulnerability - CVE-2015-0004 (MS15-003)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0004" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0004"/>
        <description>The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges by conducting a junction attack to load another user's UsrClass.dat registry hive, aka MSRC ID 20674 or "Microsoft User Profile Service Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T10:55:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:14:17.736-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:19.364-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:16.284-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of userenv.dll is less than 5.2.3790.5491" test_ref="oval:org.mitre.oval:tst:136728"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable version">
          <criteria operator="OR" comment="Vista (x86/x64) / 2k8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Profsvc.dll is less than 6.0.6002.19250" test_ref="oval:org.mitre.oval:tst:137272"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Profsvc.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137569"/>
              <criterion comment="Check if the version of Profsvc.dll is less than or equal to 6.0.6002.23557" test_ref="oval:org.mitre.oval:tst:137532"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable files version">
          <criteria operator="OR" comment="Win7 (x86/x64) / 2k8R2 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Profsvc.dll is less than 6.1.7601.18706" test_ref="oval:org.mitre.oval:tst:137372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Profsvc.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137095"/>
              <criterion comment="Check if the version of Profsvc.dll is less than 6.1.7601.22913" test_ref="oval:org.mitre.oval:tst:137455"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable files version">
          <criteria operator="OR" comment="Win8 (x86/x64) / 2k12 (x64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Profsvc.dll is less than 6.2.9200.17219" test_ref="oval:org.mitre.oval:tst:137592"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Profsvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137468"/>
              <criterion comment="Check if the version of Profsvc.dll is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/ 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Profsvc.dll is less than 6.3.9600.17552" test_ref="oval:org.mitre.oval:tst:137408"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28329" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6330 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2014-6330" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6330" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:10:02.035-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:32.328-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:35.825-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28328" version="3" class="vulnerability">
      <metadata>
        <title>OWA XSS vulnerability (CVE-2014-6326) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6326"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6325.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:18.138-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:32.118-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:35.683-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28306" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6342 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2014-6342" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6342" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6348.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:19.181-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.057-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:44.812-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28297" version="3" class="vulnerability">
      <metadata>
        <title>NLA Security Feature Bypass Vulnerability - CVE-2015-0006 (MS15-005)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0006"/>
        <description>The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T11:36:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:21:51.658-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:17.594-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:14.578-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable version">
          <criteria operator="OR" comment="Vista (x86/x64) / 2k8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Nlasvc.dll is less than 6.0.6002.19250" test_ref="oval:org.mitre.oval:tst:137124"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Nlasvc.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137327"/>
              <criterion comment="Check if the version of Nlasvc.dll is less than or equal to 6.0.6002.23557" test_ref="oval:org.mitre.oval:tst:136962"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable files version">
          <criteria operator="OR" comment="Win7 (x86/x64) / 2k8R2 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Nlasvc.dll is less than 6.1.7601.18685" test_ref="oval:org.mitre.oval:tst:137657"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Nlasvc.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137339"/>
              <criterion comment="Check if the version of Nlasvc.dll is less than 6.1.7601.22893" test_ref="oval:org.mitre.oval:tst:137638"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable files version">
          <criteria operator="OR" comment="Win8 (x86/x64) / 2k12 (x64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Nlasvc.dll is less than 6.2.9200.17199" test_ref="oval:org.mitre.oval:tst:137618"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Nlasvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137398"/>
              <criterion comment="Check if the version of Nlasvc.dll is less than 6.2.9200.21316" test_ref="oval:org.mitre.oval:tst:137617"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8.1/2k12">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Nlasvc.dll is less than 6.3.9600.17550" test_ref="oval:org.mitre.oval:tst:136722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28294" version="3" class="vulnerability">
      <metadata>
        <title>Exchange forged meeting request spoofing vulnerability  - CVE-2015-1631 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1631" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1631"/>
        <description>Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange Forged Meeting Request Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:15.438-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:06.415-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:12.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28291" version="3" class="vulnerability">
      <metadata>
        <title>OWA XSS vulnerability (CVE-2014-6325) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6325" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6325"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6326.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:19.017-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:28.586-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:32.459-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28213" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 CU 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu6"/>
        <description>Microsoft Exchange Server 2013 CU 6 is installed. Microsoft Exchange Server is calendaring software, a mail server and contact manager developed by Microsoft.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T14:23:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:16.589-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:24.485-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:28.280-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
        <criterion comment="Microsoft Exchange Server Cumulative Update 6 is installed" test_ref="oval:org.mitre.oval:tst:135802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28290" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability - CVE-2014-6346 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6346" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:03:58.998-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:02.685-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:44.081-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.410-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:14.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28283" version="3" class="vulnerability">
      <metadata>
        <title>Windows audio service vulnerability - CVE-2014-6322 (MS14-071)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6322" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6322"/>
        <description>The Windows Audio service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted web site, as demonstrated by execution of web script in Internet Explorer, aka "Windows Audio Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T10:57:41">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:19:16.188-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:02.020-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:42.592-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of audiosrv.dll is less than 6.0.6002.19201" test_ref="oval:org.mitre.oval:tst:135449"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of audiosrv.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135265"/>
              <criterion comment="Check if the version of audiosrv.dll is less than 6.0.6002.23506" test_ref="oval:org.mitre.oval:tst:135327"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of audiosrv.dll is less than 6.1.7601.18619" test_ref="oval:org.mitre.oval:tst:135244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of audiosrv.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135217"/>
              <criterion comment="Check if the version of audiosrv.dll is less than 6.1.7601.22826" test_ref="oval:org.mitre.oval:tst:135372"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of audiosrv.dll is less than 6.2.9200.17134" test_ref="oval:org.mitre.oval:tst:134576"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of audiosrv.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135321"/>
              <criterion comment="Check if the version of audiosrv.dll is less than 6.2.9200.21251" test_ref="oval:org.mitre.oval:tst:135173"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of audiosrv.dll is less than 6.3.9600.17393" test_ref="oval:org.mitre.oval:tst:135290"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28272" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0068 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0068" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0039, and CVE-2015-0052.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:11.199-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:32.804-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:13.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28270" version="3" class="vulnerability">
      <metadata>
        <title>Remote Desktop Protocol (RDP) failure to audit vulnerability - CVE-2014-6318 (MS14-074)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6318" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6318"/>
        <description>The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthorized login attempts supplying valid credentials, which makes it easier for remote attackers to bypass intended access restrictions via a series of attempts, aka "Remote Desktop Protocol (RDP) Failure to Audit Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:20:29">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:34:39.323-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:01.741-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:41.881-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2k8 and vulnerable version of file">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of lsasrv.dll is less than 6.0.6002.19214" test_ref="oval:org.mitre.oval:tst:135246"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of lsasrv.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135464"/>
              <criterion comment="Check if the version of lsasrv.dll is less than 6.0.6002.23521" test_ref="oval:org.mitre.oval:tst:135454"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of lsasrv.dll is less than 6.1.7601.18637" test_ref="oval:org.mitre.oval:tst:135351"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of lsasrv.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135369"/>
              <criterion comment="Check if the version of lsasrv.dll is less than 6.1.7601.22843" test_ref="oval:org.mitre.oval:tst:135429"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / Server 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of lsasrv.dll is less than 6.2.9200.17150" test_ref="oval:org.mitre.oval:tst:135414"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of lsasrv.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135331"/>
              <criterion comment="Check if the version of lsasrv.dll is less than 6.2.9200.21269" test_ref="oval:org.mitre.oval:tst:134506"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of lsasrv.dll is less than 6.3.9600.17396" test_ref="oval:org.mitre.oval:tst:134479"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28266" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2014-6349 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6349" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6350.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:06.898-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:01.352-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:41.011-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.548-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:13.994-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28257" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-0071 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0071" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:53.643-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:32.057-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:13.356-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28234" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6347 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6347" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:19.959-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:00.149-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:38.734-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28205" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6353 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2014-6353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6353" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:18.028-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:58.623-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:35.777-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.886-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:12.087-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28204" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability - CVE-2014-6345 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2014-6345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6345" source="CVE"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:26.269-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:58.457-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:35.385-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.629-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:11.836-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28202" version="5" class="vulnerability">
      <metadata>
        <title>CNG security feature bypass vulnerability - CVE-2015-0010 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0010"/>
        <description>The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the CRYPTPROTECTMEMORY_SAME_LOGON option is used, does not check an impersonation token's level, which allows local users to bypass intended decryption restrictions by leveraging a service that (1) has a named-pipe planting vulnerability or (2) uses world-readable shared memory for encrypted data, aka "CNG Security Feature Bypass Vulnerability" or MSRC ID 20707.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:44.543-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:30.073-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:12.910-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.132-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:13.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28201" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Brush Object use after free vulnerability - CVE-2015-1726 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1726"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Brush Object Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:19.445-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:08.028-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:05.921-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28193" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0054 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0054" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:41.896-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:29.689-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:12.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28191" version="3" class="vulnerability">
      <metadata>
        <title>Kerberos checksum vulnerability - CVE-2014-6324 (MS14-068)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6324" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6324"/>
        <description>The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-20T09:09:33">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:26:00.888-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:58.137-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:34.473-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 5.2.3790.5467" test_ref="oval:org.mitre.oval:tst:135606"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8(x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.0.6002.19220" test_ref="oval:org.mitre.oval:tst:134884"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135821"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.0.6002.23527" test_ref="oval:org.mitre.oval:tst:135571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.1.7601.18658" test_ref="oval:org.mitre.oval:tst:135724"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135603"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.1.7601.22865" test_ref="oval:org.mitre.oval:tst:135774"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/ Server 2012 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8/ Server 2012 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.17172" test_ref="oval:org.mitre.oval:tst:135850"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135794"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.21289" test_ref="oval:org.mitre.oval:tst:135536"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 6.3.9600.17423" test_ref="oval:org.mitre.oval:tst:135721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28177" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6341 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-6341" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6341" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4143.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:23.663-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:57.649-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:33.392-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28177 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:10.277-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:11.105-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28172" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer XSS filter bypass vulnerability - CVE-2014-6328 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6328" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6365.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:48.054-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:23.134-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:26.718-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28167" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1711 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1711" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1717, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:11.406-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:13.660-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:07.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28162" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1706 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1706" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1711, CVE-2015-1717, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:15:55.138-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:13.347-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:07.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28116" version="4" class="vulnerability">
      <metadata>
        <title>ASP.NET information disclosure vulnerability - CVE-2015-1648 (MS15-041)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1648"/>
        <description>ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka "ASP.NET Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:27:19.660-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:11.804-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:16.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28116 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:17.364-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of System.web.dll is less than 1.1.4322.2515" test_ref="oval:org.mitre.oval:tst:138007"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of System.Web.dll is less than 2.0.50727.3668" test_ref="oval:org.mitre.oval:tst:138523"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8656" test_ref="oval:org.mitre.oval:tst:138479"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.4257" test_ref="oval:org.mitre.oval:tst:138599"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:100649"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of the system.web.dll is less than 2.0.50727.6427" test_ref="oval:org.mitre.oval:tst:138417"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138563"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.5491" test_ref="oval:org.mitre.oval:tst:137695"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of Setup.exe is less than 10.0.30319.1031" test_ref="oval:org.mitre.oval:tst:138047"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of Setup.exe is less than 10.0.30319.2056" test_ref="oval:org.mitre.oval:tst:138530"/>
              <criterion comment="Check if the version of Setup.exe is greater than or equal to 10.0.30319.2000" test_ref="oval:org.mitre.oval:tst:100142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.34249" test_ref="oval:org.mitre.oval:tst:138462"/>
            <criteria operator="AND" comment="ldr range for system.wen.dll">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.36285" test_ref="oval:org.mitre.oval:tst:138259"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138465"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138513"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138171"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138465"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138513"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138171"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138465"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28101" version="3" class="vulnerability">
      <metadata>
        <title>EMF processing remote code execution vulnerability - CVE-2015-1645 (MS15-035)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1645" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1645"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to execute arbitrary code via a crafted Enhanced Metafile (EMF) image, aka "EMF Processing Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T09:50:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:18:33.353-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:11.502-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:16.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 vulnerable version">
          <criteria operator="OR" comment="Server (2003 - x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdi32.dll is less than 5.2.3790.5563" test_ref="oval:org.mitre.oval:tst:138531"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.19331" test_ref="oval:org.mitre.oval:tst:137581"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87308"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.23639" test_ref="oval:org.mitre.oval:tst:137985"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.18778" test_ref="oval:org.mitre.oval:tst:138384"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:87215"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.22982" test_ref="oval:org.mitre.oval:tst:137897"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28084" version="3" class="vulnerability">
      <metadata>
        <title>Graphics component information disclosure vulnerability - CVE-2014-6355 (MS14-085)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6355"/>
        <description>The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly process JPEG images, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Graphics Component Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T09:19:02">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:31:57.318-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:21.699-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:24.183-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdiplus.dll is less than 5.2.6002.23535" test_ref="oval:org.mitre.oval:tst:135635"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is less than 7.0.6002.23535" test_ref="oval:org.mitre.oval:tst:135554"/>
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135896"/>
            </criteria>
            <criterion comment="Check if the version of windowscodecs.dll is less than 7.0.6002.19227" test_ref="oval:org.mitre.oval:tst:135918"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.21283" test_ref="oval:org.mitre.oval:tst:135814"/>
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
            </criteria>
            <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.17170" test_ref="oval:org.mitre.oval:tst:135865"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.17170" test_ref="oval:org.mitre.oval:tst:135865"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.21283" test_ref="oval:org.mitre.oval:tst:135814"/>
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of windowscodecs.dll is less than 6.3.9600.17483" test_ref="oval:org.mitre.oval:tst:135833"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28080" version="3" class="vulnerability">
      <metadata>
        <title>MSXML Remote Code Execution Vulnerability - CVE-2014-4118 (MS14-067)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft XML Core Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4118"/>
        <description>XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (system-state corruption) via crafted XML content, aka "MSXML Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T09:35:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:01:01.543-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:55.185-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:29.590-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2003/version">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.1056.0" test_ref="oval:org.mitre.oval:tst:135335"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/versions/Core services 3.0">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.5009.0" test_ref="oval:org.mitre.oval:tst:135467"/>
        </criteria>
        <criteria operator="AND" comment="win7/2008 r2/versions/Core services 3.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.18576" test_ref="oval:org.mitre.oval:tst:135472"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.22782" test_ref="oval:org.mitre.oval:tst:135435"/>
              <criterion comment="Check if version of Msxml3.dll is greater than or equal to 8.110.7601.22000" test_ref="oval:org.mitre.oval:tst:79072"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
        </criteria>
        <criteria operator="AND" comment="win8/2012/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.17092" test_ref="oval:org.mitre.oval:tst:135230"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.21211" test_ref="oval:org.mitre.oval:tst:135159"/>
              <criterion comment="Check if the version of msxml3.dll is greater than or equal to 8.110.9200.21000" test_ref="oval:org.mitre.oval:tst:135330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8.1/2012 r2/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9600.17324" test_ref="oval:org.mitre.oval:tst:135153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28068" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1678 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1678"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1677, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:11.771-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:12.565-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:04.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28056" version="4" class="vulnerability">
      <metadata>
        <title>TypeFilterLevel vulnerability - CVE-2014-4149 (MS14-072)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4149"/>
        <description>Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T15:16:57.075+05:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:25:39.643-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:53.895-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:26.757-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28056 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:19.832-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of system.runtime.remoting.dll is less than 1.1.4322.2511" test_ref="oval:org.mitre.oval:tst:135048"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.3664" test_ref="oval:org.mitre.oval:tst:135127"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8642" test_ref="oval:org.mitre.oval:tst:135376"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.4255" test_ref="oval:org.mitre.oval:tst:134767"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.6424" test_ref="oval:org.mitre.oval:tst:135177"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8012" test_ref="oval:org.mitre.oval:tst:135204"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.5488" test_ref="oval:org.mitre.oval:tst:135034"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.1030" test_ref="oval:org.mitre.oval:tst:135427"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.2049" test_ref="oval:org.mitre.oval:tst:135401"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:113636"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34245" test_ref="oval:org.mitre.oval:tst:135408"/>
            <criteria operator="AND" comment="ldr range for system.wen.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36257" test_ref="oval:org.mitre.oval:tst:135325"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:135009"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:135389"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.52 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:135009"/>
            <criteria operator="AND" comment="ldr range for mscorlib.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:135389"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28046" version="5" class="vulnerability">
      <metadata>
        <title>Windows OLE automation array remote code execution vulnerability - CVE-2014-6332 (MS14-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6332" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6332"/>
        <description>OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T09:19:02">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T16:51:30.079-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:53.465-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:25.144-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="the version of oleaut32.dll is less than 5.2.3790.5464" test_ref="oval:org.mitre.oval:tst:135145"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.0.6002.19220" test_ref="oval:org.mitre.oval:tst:134817"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:125246"/>
              <criterion comment="Check if version of Packager.dll is less than 6.0.6002.23527" test_ref="oval:org.mitre.oval:tst:134430"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the the version of Oleaut32.dll is less than 6.0.6002.23523" test_ref="oval:org.mitre.oval:tst:135387"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135348"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.0.6002.19216" test_ref="oval:org.mitre.oval:tst:135047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.1.7601.18645" test_ref="oval:org.mitre.oval:tst:135398"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:125217"/>
              <criterion comment="Check if version of Packager.dll is less than 6.1.7601.22853" test_ref="oval:org.mitre.oval:tst:134892"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.22846" test_ref="oval:org.mitre.oval:tst:135363"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135416"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.18640" test_ref="oval:org.mitre.oval:tst:135320"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.21278" test_ref="oval:org.mitre.oval:tst:135137"/>
              <criterion comment="Check if the version of Packager.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:124862"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.21273" test_ref="oval:org.mitre.oval:tst:135117"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135377"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.17155" test_ref="oval:org.mitre.oval:tst:135036"/>
            <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.17160" test_ref="oval:org.mitre.oval:tst:135423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of packager.dll is less than 6.3.9600.17408" test_ref="oval:org.mitre.oval:tst:135370"/>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.3.9600.17403" test_ref="oval:org.mitre.oval:tst:135178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28021" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0050 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0050" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0044.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:02.226-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:27.597-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:11.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28018" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability - CVE-2015-0070 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0070" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:02.795-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:27.194-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:10.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28017" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6344 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2014-6344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6344" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:04.055-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:52.783-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:23.989-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27987" version="3" class="vulnerability">
      <metadata>
        <title>WTS remote code execution vulnerability - CVE-2015-0081 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0081"/>
        <description>Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:49:15.398-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:05.473-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:12.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msctf.dll is less than 5.2.3790.5528" test_ref="oval:org.mitre.oval:tst:138159"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.19296" test_ref="oval:org.mitre.oval:tst:138055"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138164"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.23606" test_ref="oval:org.mitre.oval:tst:138244"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.18731" test_ref="oval:org.mitre.oval:tst:138228"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137811"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.22937" test_ref="oval:org.mitre.oval:tst:138300"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.17243" test_ref="oval:org.mitre.oval:tst:138380"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138364"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.21361" test_ref="oval:org.mitre.oval:tst:138214"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version msctf.dll is less than 6.3.9600.17664" test_ref="oval:org.mitre.oval:tst:138210"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27984" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft IME (Japanese) elevation of privilege vulnerability - CVE-2014-4077 (MS14-078)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Input Method Editor Japanese</product>
          <product>Microsoft Office IME Japanese 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4077"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka "Microsoft IME (Japanese) Elevation of Privilege Vulnerability," as exploited in the wild in 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:39:54.975-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:52.349-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:23.086-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="office 2007 IME Japanese and vulnerable version">
          <extend_definition comment="Microsoft Office 2007 IME Japanese is installed" definition_ref="oval:org.mitre.oval:def:27826"/>
          <criterion comment="Check if the version of Imjputyc.dll is less than 12.0.6704.5000 (Office IME japanese)" test_ref="oval:org.mitre.oval:tst:135443"/>
        </criteria>
        <criteria operator="AND" comment="OS and vulnerable version">
          <extend_definition comment="Microsoft Input method editor (IME) Japanese is installed" definition_ref="oval:org.mitre.oval:def:28268"/>
          <criteria operator="OR" comment="OS and Vuln file version">
            <criteria operator="AND" comment="2K3 and vulnerable file version">
              <criteria operator="OR" comment="Either OS">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of Imjputyc.dll is less than 8.1.7104.0" test_ref="oval:org.mitre.oval:tst:135444"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="GDR / LDR">
                <criterion comment="Check if the version of Imjputyc.dll is less than 10.0.6002.19154" test_ref="oval:org.mitre.oval:tst:135298"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Check if the version of Imjputyc.dll is less than 10.0.6002.23459" test_ref="oval:org.mitre.oval:tst:135503"/>
                  <criterion comment="Check if the version of Imjputyc.dll is greater than or equal to 10.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135478"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2008 R2 + vulnerable file version">
              <criteria operator="OR" comment="Win 7 / 2008 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="GDR / LDR">
                <criterion comment="Check if the version of Imjputyc.dll is less than 10.1.7601.18556" test_ref="oval:org.mitre.oval:tst:135473"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Check if the version of Imjputyc.dll is less than 10.1.7601.22764" test_ref="oval:org.mitre.oval:tst:135470"/>
                  <criterion comment="Check if the version of Imjputyc.dll is greater than or equal to 10.1.7601.22000" test_ref="oval:org.mitre.oval:tst:134765"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28268" version="3" class="inventory">
      <metadata>
        <title>Microsoft Input method editor (IME) Japanese is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Input Method Editor Japanese</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ime:japanese"/>
        <description>Microsoft Input method editor (IME) Japanese is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T07:13:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:39:53.705-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:01.682-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:41.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft IME (Japanese) is installed" test_ref="oval:org.mitre.oval:tst:134883"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27826" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office 2007 IME Japanese is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Office IME Japanese 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:2007:::ime_japanese"/>
        <description>Microsoft Office 2007 IME Japanese is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T07:13:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:39:53.099-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:50.352-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:19.377-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Office 2007 IME Japanese is installed" test_ref="oval:org.mitre.oval:tst:135203"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27977" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0041 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0041" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, and CVE-2015-0036.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:25.392-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:26.618-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:09.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27957" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0042 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0042" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0038 and CVE-2015-0046.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:47.830-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:25.792-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:09.257-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27932" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer XSS filter bypass vulnerability - CVE-2014-6365 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6365" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6328.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:58.737-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:16.226-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:17.011-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27923" version="3" class="vulnerability">
      <metadata>
        <title>Windows OLE remote code execution vulnerability - CVE-2014-6352 (MS14-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6352"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T09:19:02">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T16:51:32.554-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:51.571-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:21.713-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.0.6002.19220" test_ref="oval:org.mitre.oval:tst:134817"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:125246"/>
              <criterion comment="Check if version of Packager.dll is less than 6.0.6002.23527" test_ref="oval:org.mitre.oval:tst:134430"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the the version of Oleaut32.dll is less than 6.0.6002.23523" test_ref="oval:org.mitre.oval:tst:135387"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135348"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.0.6002.19216" test_ref="oval:org.mitre.oval:tst:135047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.1.7601.18645" test_ref="oval:org.mitre.oval:tst:135398"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:125217"/>
              <criterion comment="Check if version of Packager.dll is less than 6.1.7601.22853" test_ref="oval:org.mitre.oval:tst:134892"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.22846" test_ref="oval:org.mitre.oval:tst:135363"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135416"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.18640" test_ref="oval:org.mitre.oval:tst:135320"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.21278" test_ref="oval:org.mitre.oval:tst:135137"/>
              <criterion comment="Check if the version of Packager.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:124862"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.21273" test_ref="oval:org.mitre.oval:tst:135117"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135377"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.17155" test_ref="oval:org.mitre.oval:tst:135036"/>
            <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.17160" test_ref="oval:org.mitre.oval:tst:135423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of packager.dll is less than 6.3.9600.17408" test_ref="oval:org.mitre.oval:tst:135370"/>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.3.9600.17403" test_ref="oval:org.mitre.oval:tst:135178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27908" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1667 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1667" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1667" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:15.343-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:11.081-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:15.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27900" version="3" class="vulnerability">
      <metadata>
        <title>Exchange error message cross site scripting vulnerability - CVE-2015-1632 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1632"/>
        <description>Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via the msgParam parameter in an authError action, aka "Exchange Error Message Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:14.644-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:05.298-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:12.014-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28846" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 Cumulative Update 7 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu7"/>
        <description>Microsoft Exchange Server 2013 Cumulative Update 7 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:13.692-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.874-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.847-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 Cumulative Update 7 is installed" test_ref="oval:org.mitre.oval:tst:138458"/>
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27899" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1652 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1652" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1666.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:11.748-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:09.743-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:14.803-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27897" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2014-6350 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6350" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6350" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6349.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:15.603-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:50.776-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:20.204-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:13.029-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:06.317-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27875" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint xss vulnerability – CVE-2015-1633 (MS15-022)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1633"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T17:47:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T10:00:06.481-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:04.604-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:11.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.846-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:12.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7145.5000" test_ref="oval:org.mitre.oval:tst:138365"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138170"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138254"/>
            <criterion comment="Check if the version of wwintl.dll is less than 15.0.4631.1000" test_ref="oval:org.mitre.oval:tst:138441"/>
            <criterion comment="Check if the version of vutils.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138393"/>
            <criterion comment="Check if the version of microsoft.office.infopath.server.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138339"/>
            <criterion comment="Check if the version of ascalc.dll is less than 15.0.4699.1000" test_ref="oval:org.mitre.oval:tst:138351"/>
            <criterion comment="Check if the version of msoserverintl.dll is less than 15.0.4697.1000" test_ref="oval:org.mitre.oval:tst:138449"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7145.5000" test_ref="oval:org.mitre.oval:tst:138454"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27824" version="4" class="vulnerability">
      <metadata>
        <title>SharePoint elevation of privilege vulnerability - CVE-2014-4116 (MS14-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4116"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject arbitrary web script or HTML via a modified list, aka "SharePoint Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T10:39:40">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:29:43.671-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-12-08T04:00:50.207-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:19.171-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if the version of Onetutil.dll is less than 14.0.7137.5000" test_ref="oval:org.mitre.oval:tst:134500"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27794" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft schannel remote code execution vulnerability - CVE-2014-6321 (MS14-066)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6321"/>
        <description>Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via crafted packets, aka "Microsoft Schannel Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T16:54:12.821-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:49.726-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:18.310-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135297 - States changed in accordance with MS14-066" date="2015-02-03T13:31:00.917-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:32:49.343-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:04.824-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5462" test_ref="oval:org.mitre.oval:tst:135027"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Schannnel.dll is less than 6.0.6002.23555" test_ref="oval:org.mitre.oval:tst:135415"/>
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:134478"/>
            </criteria>
            <criterion comment="Check if the version of Schannnel.dll is less than 6.0.6002.19247" test_ref="oval:org.mitre.oval:tst:135297"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Schannnel.dll is less than 6.1.7601.22814" test_ref="oval:org.mitre.oval:tst:135229"/>
              <criterion comment="Check if the version of schannel.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135418"/>
            </criteria>
            <criterion comment="Check if the version of Schannnel.dll is less than 6.1.7601.18606" test_ref="oval:org.mitre.oval:tst:135054"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Schannnel.dll is less than 6.2.9200.21241" test_ref="oval:org.mitre.oval:tst:135152"/>
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135406"/>
            </criteria>
            <criterion comment="Check if the version of Schannnel.dll is less than 6.2.9200.17124" test_ref="oval:org.mitre.oval:tst:135393"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Schannnel.dll is less than 6.3.9600.17385" test_ref="oval:org.mitre.oval:tst:135346"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27772" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0067 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0067" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0067" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:57.097-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:24.683-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:08.159-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27768" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service in Windows Kernel Mode Driver vulnerability - CVE-2014-6317 (MS14-079)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6317"/>
        <description>Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font, aka "Denial of Service in Windows Kernel Mode Driver Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:42:02.670-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:49.272-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:17.526-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5448" test_ref="oval:org.mitre.oval:tst:135249"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19215" test_ref="oval:org.mitre.oval:tst:135422"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23522" test_ref="oval:org.mitre.oval:tst:135446"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18618" test_ref="oval:org.mitre.oval:tst:135115"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22825" test_ref="oval:org.mitre.oval:tst:134694"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17133" test_ref="oval:org.mitre.oval:tst:135502"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21250" test_ref="oval:org.mitre.oval:tst:135138"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17393" test_ref="oval:org.mitre.oval:tst:135314"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27765" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0029 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0029" source="CVE"/>
        <description>Microsoft Internet Explorer 6 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:49.416-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:23.440-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:06.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27743" version="3" class="vulnerability">
      <metadata>
        <title>WebDAV elevation of privilege vulnerability - CVE-2015-0011 (MS15-008)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0011" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0011"/>
        <description>mrxdav.sys (aka the WebDAV driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass an impersonation protection mechanism, and obtain privileges for redirection of WebDAV requests, via a crafted application, aka "WebDAV Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T11:10:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:40:17.323-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:11.062-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:04.425-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64/ia64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Mrxdav.sys is less than 5.2.3790.5508" test_ref="oval:org.mitre.oval:tst:137458"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Mrxdav.sys is less than 6.0.6002.19273" test_ref="oval:org.mitre.oval:tst:137689"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Mrxdav.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137580"/>
              <criterion comment="Check if the version of Mrxdav.sys is less than 6.0.6002.23581" test_ref="oval:org.mitre.oval:tst:137584"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Mrxdav.sys is less than 6.1.7601.18706" test_ref="oval:org.mitre.oval:tst:137159"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Mrxdav.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137531"/>
              <criterion comment="Check if the version of Mrxdav.sys is less than 6.1.7601.22913" test_ref="oval:org.mitre.oval:tst:137072"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Mrxdav.sys is less than 6.2.9200.17219" test_ref="oval:org.mitre.oval:tst:137126"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Mrxdav.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137739"/>
              <criterion comment="Check if the version of Mrxdav.sys is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137171"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Mrxdav.sys is less than 6.3.9600.17560" test_ref="oval:org.mitre.oval:tst:137442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27704" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6369 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6369" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6369" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:56.129-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:12.173-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:12.899-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27676" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2014-6339 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2014-6339" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6339" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:05.680-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:47.604-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:14.934-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27601" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6351 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6351" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:02.624-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:46.770-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:13.695-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:11.794-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:01.428-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 )">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27489" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6348 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2014-6348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6348" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6342.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:24.822-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:45.867-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:11.514-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27372" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6337 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6337" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:00.311-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:45.463-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:10.621-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27372 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:10.031-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:59.833-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27356" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-4143 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-4143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4143" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6341.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:29.448-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:44.873-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:08.407-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.726-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:59.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27094" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4129 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4129" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4129"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:59.986-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:37.430-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:12.979-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27076" version="3" class="vulnerability">
      <metadata>
        <title>Win32k.sys elevation of privilege vulnerability - CVE-2014-4113 (MS14-058)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4113"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:49:57.819-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:36.052-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:06.596-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5445" test_ref="oval:org.mitre.oval:tst:124336"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19198" test_ref="oval:org.mitre.oval:tst:125108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23504" test_ref="oval:org.mitre.oval:tst:124868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18615" test_ref="oval:org.mitre.oval:tst:124383"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22823" test_ref="oval:org.mitre.oval:tst:125245"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17130" test_ref="oval:org.mitre.oval:tst:125211"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21247" test_ref="oval:org.mitre.oval:tst:124497"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17353" test_ref="oval:org.mitre.oval:tst:124547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27069" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4130 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4130" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4130"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4132 and CVE-2014-4138.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:55.435-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:35.864-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:02.401-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27037" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4126 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4126"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:36.753-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:31.554-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:49.270-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27003" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer ASLR bypass vulnerability - CVE-2014-4140 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4140"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:49.855-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:30.558-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:41.032-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26997" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4127 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4127"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:34.718-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:30.199-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:39.585-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5424" test_ref="oval:org.mitre.oval:tst:125117"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26979" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4134 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4134"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:44.360-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:29.876-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:35.191-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5424" test_ref="oval:org.mitre.oval:tst:125117"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26918" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4141 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4141"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:46.744-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:25.888-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:18.902-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26910" version="4" class="vulnerability">
      <metadata>
        <title>.NET ClickOnce elevation of privilege vulnerability - CVE-2014-4073 (MS14-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4073"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:45:32.858-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:23.204-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:14.669-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26910 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:19.056-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.3663" test_ref="oval:org.mitre.oval:tst:125235"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.4255" test_ref="oval:org.mitre.oval:tst:125162"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.6424" test_ref="oval:org.mitre.oval:tst:124755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.8012" test_ref="oval:org.mitre.oval:tst:124677"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.5488" test_ref="oval:org.mitre.oval:tst:124855"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win server 2003/vista/server 2008/Win 7/ server 2008 R2 and vuln versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.2048" test_ref="oval:org.mitre.oval:tst:125121"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:124753"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.1029" test_ref="oval:org.mitre.oval:tst:125047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR range">
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.34244" test_ref="oval:org.mitre.oval:tst:124990"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.36256" test_ref="oval:org.mitre.oval:tst:125179"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:125206"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:125063"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:125206"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:125250"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:125063"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:125206"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:125250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26903" version="3" class="vulnerability">
      <metadata>
        <title>.NET ASLR vulnerability  - CVE-2014-4122 (MS14-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4122"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location, aka ".NET ASLR Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:45:35.478-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:22.952-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:13.490-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.4252" test_ref="oval:org.mitre.oval:tst:125200"/>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.6419" test_ref="oval:org.mitre.oval:tst:125164"/>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.8008" test_ref="oval:org.mitre.oval:tst:124856"/>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.5483" test_ref="oval:org.mitre.oval:tst:124996"/>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26879" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4093 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4093"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4084.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:50.738-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:11.038-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:45.409-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26864" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4096 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4096"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4087, CVE-2014-4095, and CVE-2014-4101.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:14.221-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:10.671-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:43.210-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
          </criteria>
          <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26862" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4082 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4082"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:01.071-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:10.375-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:42.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26855" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4088 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4088"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:22.289-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:09.684-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:42.072-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26850" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4128 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4128"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:52.859-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:21.745-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:00.404-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5424" test_ref="oval:org.mitre.oval:tst:125117"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26849" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4065 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4065"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:42.580-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:09.339-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:41.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26847" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4095 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4095"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4087, CVE-2014-4096, and CVE-2014-4101.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:27.813-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:09.223-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:41.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
          </criteria>
          <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26846" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4081 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4081"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:04.714-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:08.906-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:41.016-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26823" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4132 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4132"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4130 and CVE-2014-4138.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:29:01.496-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:21.193-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:57.016-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26815" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4108 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4108"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:14.215-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:07.710-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:38.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26811" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4104 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4104"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:36.085-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:07.096-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:37.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26798" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4105 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4105"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:07.380-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:06.429-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:36.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26791" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4107 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4107"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:53.707-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.896-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:35.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26788" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4099 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4099"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:11.466-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.622-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:35.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26785" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4103 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4103"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:13.333-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.362-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:34.769-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26780" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4101 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4101" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4101"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4087, CVE-2014-4095, and CVE-2014-4096.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:23.216-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.155-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:34.099-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
          </criteria>
          <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26757" version="4" class="vulnerability">
      <metadata>
        <title>.NET Framework remote code execution vulnerability  - CVE-2014-4121 (MS14-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4121"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:45:40.018-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:16.786-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:49.183-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26757 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:18.326-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 2.0.50727.8637" test_ref="oval:org.mitre.oval:tst:124441"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:124979"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.3662" test_ref="oval:org.mitre.oval:tst:124945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dl is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124941"/>
              <criterion comment="Check if the version of System.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:125120"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.4253" test_ref="oval:org.mitre.oval:tst:125045"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dl is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124941"/>
              <criterion comment="Check if the version of System.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:125120"/>
            </criteria>
            <criterion comment="Check if the version of the system.dll is less than 2.0.50727.6421" test_ref="oval:org.mitre.oval:tst:125243"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 2.0.50727.8615" test_ref="oval:org.mitre.oval:tst:124983"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:124979"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.8009" test_ref="oval:org.mitre.oval:tst:125152"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dl is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124941"/>
              <criterion comment="Check if the version of System.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:125120"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.5485" test_ref="oval:org.mitre.oval:tst:125005"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win server 2003/vista/server 2008/Win 7/ server 2008 R2 and vuln versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.2045" test_ref="oval:org.mitre.oval:tst:125168"/>
              <criterion comment="Check if the version of system.dl is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:125128"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.1026" test_ref="oval:org.mitre.oval:tst:125066"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR range">
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.36250" test_ref="oval:org.mitre.oval:tst:125169"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124981"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.34238" test_ref="oval:org.mitre.oval:tst:125064"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.36251" test_ref="oval:org.mitre.oval:tst:125056"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124981"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.34239" test_ref="oval:org.mitre.oval:tst:125032"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.36251" test_ref="oval:org.mitre.oval:tst:125056"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124981"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.34239" test_ref="oval:org.mitre.oval:tst:125032"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26746" version="3" class="vulnerability">
      <metadata>
        <title>Alows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3876"/>
        <description>DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-19T15:06:07.129-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:03.860-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:30.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Oakley.dll and XP">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Oakley.dll is less than 5.1.2600.6462" test_ref="oval:org.mitre.oval:tst:123290"/>
        </criteria>
        <criteria operator="AND" comment="Oakley.dll and XP or 2003">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Oakley.dll is less than 5.2.3790.5238" test_ref="oval:org.mitre.oval:tst:123609"/>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and Vista or 2008">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Ikeext.dll is less than 6.0.6002.18960" test_ref="oval:org.mitre.oval:tst:122774"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of Ikeext.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:123713"/>
              <criterion comment="Check if the version of Ikeext.dll is less than 6.0.6002.23243" test_ref="oval:org.mitre.oval:tst:123737"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and 7 or 2008R2">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Ikeext.dll is less than 6.1.7601.18283" test_ref="oval:org.mitre.oval:tst:123545"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of Ikeext.dll is less than 6.1.7601.22479" test_ref="oval:org.mitre.oval:tst:123653"/>
              <criterion comment="Check if the version of Ikeext.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:123216"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and 8 or 2012">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Ikeext.dll is less than 6.2.9200.16734" test_ref="oval:org.mitre.oval:tst:123603"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of Ikeext.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:123707"/>
              <criterion comment="Check if the version of Ikeext.dll is less than 6.2.9200.20846" test_ref="oval:org.mitre.oval:tst:123157"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and 8.1 or 2012R2">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ikeext.dll is less than 6.3.9600.16427" test_ref="oval:org.mitre.oval:tst:123120"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26733" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer elevation of privilege vulnerability - CVE-2014-4124 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4124"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-4123.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:40.127-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:15.863-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:46.649-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26730" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4138 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4138"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4130 and CVE-2014-4132.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:47.940-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:15.588-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:46.090-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26726" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4092 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4092"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4098.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:09.687-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:02.645-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:28.340-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26693" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4089 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4089"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4091, and CVE-2014-4102.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:43.809-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:59.575-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:24.753-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26686" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4087 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4087"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4095, CVE-2014-4096, and CVE-2014-4101.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:01.827-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.792-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:23.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
          </criteria>
          <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26683" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4111 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4111"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, and CVE-2014-4110.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:59.525-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.412-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:23.038-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26682" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4106 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4106"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:56.660-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.206-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:22.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26680" version="3" class="vulnerability">
      <metadata>
        <title>Lync Denial of Service vulnerability (CVE-2014-4068) - MS14-055</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2013</product>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4068"/>
        <description>The Response Group Service in Microsoft Lync Server 2010 and 2013 and the Core Components in Lync Server 2013 do not properly handle exceptions, which allows remote attackers to cause a denial of service (daemon hang) via a crafted call, aka "Lync Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T17:08:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:56.842-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.073-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:22.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Lync server 2013 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16524"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 5.0.8308.803" test_ref="oval:org.mitre.oval:tst:123294"/>
            <criterion comment="Check if the version of Deploy.resources.dll is less than 5.0.8308.420" test_ref="oval:org.mitre.oval:tst:123329"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Lync server 2010 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:26794"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of wrtces.dll is less than 4.0.7577.230" test_ref="oval:org.mitre.oval:tst:123304"/>
            <criterion comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 4.0.7577.276" test_ref="oval:org.mitre.oval:tst:122801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26677" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4098 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4098"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4092.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:04.777-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:57.299-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:21.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26674" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4097 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4097"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:27.034-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:56.856-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:21.023-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26669" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4090 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4090"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:53.722-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:56.070-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:20.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26664" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer elevation of privilege vulnerability - CVE-2014-4123 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4123"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:58.383-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:14.671-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:40.683-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26663" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4100 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4100"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:02.495-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:55.290-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:19.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26651" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-2799 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2799"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:56.380-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:54.508-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:18.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26645" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4059 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4059"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:10.493-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:53.892-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:17.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26621" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4083 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4083"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:33.364-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:51.659-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:12.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26613" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4079 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4079"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:39.523-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:51.145-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:11.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26611" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer resource information disclosure vulnerability - CVE-2013-7331 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-7331" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7331"/>
        <description>The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:17.303-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:50.792-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:11.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26610" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4086 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4086"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:19.228-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:50.614-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:10.879-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26601" version="4" class="vulnerability">
      <metadata>
        <title>.NET framework denial of service vulnerability - CVE-2014-4072 (MS14-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4072"/>
        <description>Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka ".NET Framework Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-15T15:56:34.779-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:13.105-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:35.446-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26601 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:19.419-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 1.1 sp1/versions">
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2510" test_ref="oval:org.mitre.oval:tst:124781"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.3662" test_ref="oval:org.mitre.oval:tst:125038"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8637" test_ref="oval:org.mitre.oval:tst:124978"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:121706"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.4253" test_ref="oval:org.mitre.oval:tst:124901"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124564"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.0 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15312"/>
          <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.4068" test_ref="oval:org.mitre.oval:tst:125058"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of system.identitymodel.dll is less than 3.0.4506.4222" test_ref="oval:org.mitre.oval:tst:124817"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.0 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15312"/>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.5485" test_ref="oval:org.mitre.oval:tst:125118"/>
            <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.5463" test_ref="oval:org.mitre.oval:tst:125060"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124564"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.6421" test_ref="oval:org.mitre.oval:tst:125017"/>
            <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.6415" test_ref="oval:org.mitre.oval:tst:124404"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124564"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win server 2003/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.1026" test_ref="oval:org.mitre.oval:tst:125136"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.2045" test_ref="oval:org.mitre.oval:tst:124886"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.34234" test_ref="oval:org.mitre.oval:tst:125089"/>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.34230" test_ref="oval:org.mitre.oval:tst:125134"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.36241" test_ref="oval:org.mitre.oval:tst:124665"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.34230" test_ref="oval:org.mitre.oval:tst:125134"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.36241" test_ref="oval:org.mitre.oval:tst:124665"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8002" test_ref="oval:org.mitre.oval:tst:124659"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8009" test_ref="oval:org.mitre.oval:tst:124916"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8615" test_ref="oval:org.mitre.oval:tst:124861"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:121706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26546" version="4" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 4.5.2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:4.5:sp2"/>
        <description>Microsoft .NET Framework 4.5.2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-15T15:56:34.014-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:12.370-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:30.753-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26546 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:18.096-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Either release version">
          <criterion comment="Check if the release version of .Net framework 4.5 (client) is equal 379893" test_ref="oval:org.mitre.oval:tst:125079"/>
          <criterion comment="Check if the release version of .Net framework 4.5 (full) is equal to 379893" test_ref="oval:org.mitre.oval:tst:124744"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26594" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4080 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4080"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4089, CVE-2014-4091, and CVE-2014-4102.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:58.754-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:49.481-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:08.967-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26550" version="3" class="vulnerability">
      <metadata>
        <title>Lync Denial of Service vulnerability (CVE-2014-4071) - MS14-055</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2013</product>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4071"/>
        <description>The Server in Microsoft Lync Server 2013 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon hang) via a crafted request, aka "Lync Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T17:08:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:56.412-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:45.038-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:01.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Lync server 2013 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16524"/>
          <criterion comment="Check if the version of SIPStack.dll is less than 5.0.8308.803" test_ref="oval:org.mitre.oval:tst:123219"/>
        </criteria>
        <criteria operator="AND" comment="Lync server 2010 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:26794"/>
          <criterion comment="Check if the version of wrtces.dll is less than 4.0.7577.230" test_ref="oval:org.mitre.oval:tst:123304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26794" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_server:2010"/>
        <description>Microsoft Lync Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T15:07:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:55.728-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:06.363-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:36.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:123575"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16524" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Lync Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_server:2013"/>
        <description>Microsoft Lync Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T15:07:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:55:37.927-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:01:08.247-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:00:49.126-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:81027"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26515" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2782"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-11T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:44.556-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:24.512-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:35.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26479" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4056 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4056"/>
        <description>Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:29.754-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:59.449-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:41.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26467" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2774 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2774"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2820, CVE-2014-2826, CVE-2014-2827, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:10.821-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:59.174-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:40.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26456" version="4" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0325" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0325"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site that triggers improper processing of CElement objects, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1751 and CVE-2014-1755.  NOTE: MS14-018 originally had a typo of CVE-2014-0235 for this.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:39.799-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:21.851-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:31.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="either 2k8, 2k8 R2, Win 7 / Vista">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
        </criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="GDR / LDR">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16545" test_ref="oval:org.mitre.oval:tst:113555"/>
          <criteria operator="AND" comment="LDR range">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20656" test_ref="oval:org.mitre.oval:tst:113735"/>
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26452" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2818 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2818"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:04.469-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.745-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:39.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26442" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege vulnerability - CVE-2014-0318 (MS14-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0318" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0318"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control access to thread-owned objects, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:55:08.124-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.530-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:38.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2K3(all) and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5398" test_ref="oval:org.mitre.oval:tst:122069"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19150" test_ref="oval:org.mitre.oval:tst:121902"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23454" test_ref="oval:org.mitre.oval:tst:122185"/>
            </criteria>
            <criterion comment="Check if the version of Dxgkrnl.sys is less than 7.0.6002.19126" test_ref="oval:org.mitre.oval:tst:122360"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81004"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 7.0.6002.23427" test_ref="oval:org.mitre.oval:tst:122064"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18539" test_ref="oval:org.mitre.oval:tst:121806"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22750" test_ref="oval:org.mitre.oval:tst:122188"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.18510" test_ref="oval:org.mitre.oval:tst:122038"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version dxgkrnl.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81058"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.22720" test_ref="oval:org.mitre.oval:tst:122391"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17059" test_ref="oval:org.mitre.oval:tst:122363"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21178" test_ref="oval:org.mitre.oval:tst:122110"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.17031" test_ref="oval:org.mitre.oval:tst:122335"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.21148" test_ref="oval:org.mitre.oval:tst:122306"/>
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either vulnerable file">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17250" test_ref="oval:org.mitre.oval:tst:122384"/>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.3.9600.17210" test_ref="oval:org.mitre.oval:tst:122135"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26422" version="3" class="vulnerability">
      <metadata>
        <title>TrueType font parsing remote code execution vulnerability - CVE-2014-4148 (MS14-058)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4148"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:49:55.492-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:11.556-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:21.971-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5445" test_ref="oval:org.mitre.oval:tst:124336"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19198" test_ref="oval:org.mitre.oval:tst:125108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23504" test_ref="oval:org.mitre.oval:tst:124868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18615" test_ref="oval:org.mitre.oval:tst:124383"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22823" test_ref="oval:org.mitre.oval:tst:125245"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17130" test_ref="oval:org.mitre.oval:tst:125211"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21247" test_ref="oval:org.mitre.oval:tst:124497"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17353" test_ref="oval:org.mitre.oval:tst:124547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26405" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4109 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4109"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:30.374-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:37.174-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:46.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26400" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2784 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2784"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:51.966-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.289-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:36.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26399" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2810 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2810" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2810"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2811, CVE-2014-2822, CVE-2014-2823, and CVE-2014-4057.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:38.424-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.174-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:36.643-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26398" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2822 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2822"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2811, CVE-2014-2823, and CVE-2014-4057.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:46.550-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.046-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:36.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26394" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4058 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4058"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:03.556-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:57.728-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:36.377-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26382" version="3" class="vulnerability">
      <metadata>
        <title>Service Control Manager Double Free Vulnerability (MS13-077)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3862"/>
        <description>Double free vulnerability in Microsoft Windows 7 and Server 2008 R2 SP1 allows local users to gain privileges via a crafted service description that is not properly handled by services.exe in the Service Control Manager (SCM), aka "Service Control Manager Double Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-22T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-05T14:21:44.092-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:51.452-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:34.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="OS section">
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
        </criteria>
        <criteria operator="OR" comment="GDR/LDR">
          <criterion comment="Check if the version of winsrv.dll is less than 6.1.7601.18229" test_ref="oval:org.mitre.oval:tst:122366"/>
          <criteria operator="AND" comment="LDR range">
            <criterion comment="Check if the version of winsrv.dll is less than 6.1.7601.22411" test_ref="oval:org.mitre.oval:tst:122124"/>
            <criterion comment="the version of Winsrv.dll is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:43919"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26378" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability allows remote attackers to bypass Protected Mode</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1347"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:40.643-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:19.262-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:27.454-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26378 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:47.467-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:27.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16722" test_ref="oval:org.mitre.oval:tst:42403"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
            <criterion comment="Mshtml.dll version is less than 8.0.7600.20861" test_ref="oval:org.mitre.oval:tst:42393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26376" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2782) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2782"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-11T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-08-13T10:47:58.925-04:00">DRAFT</status_change>
            <status_change date="2014-09-01T04:03:13.376-04:00">INTERIM</status_change>
            <status_change date="2014-09-22T04:00:50.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26358" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2821 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2821"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:31.518-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:57.571-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:34.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26355" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer contains a flaw that may allow bypassing the elevation policy checks in the Enhanced Protected Mode and Protected Mode mechanisms - CVE-2013-4015 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-4015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4015"/>
        <description>Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-12T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-08-15T10:18:02.005-04:00">DRAFT</status_change>
            <status_change date="2014-09-01T04:03:12.477-04:00">INTERIM</status_change>
            <status_change date="2014-09-22T04:00:48.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6400" test_ref="oval:org.mitre.oval:tst:81844"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5170" test_ref="oval:org.mitre.oval:tst:81724"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21342" test_ref="oval:org.mitre.oval:tst:81752"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81698"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23133" test_ref="oval:org.mitre.oval:tst:81717"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26341" version="3" class="vulnerability">
      <metadata>
        <title>Windows installer repair vulnerability - CVE-2014-1814 (MS14-049)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1814"/>
        <description>The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that invokes the repair feature for a different application, aka "Windows Installer Repair Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:35:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:02:37.371-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:56.654-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:33.154-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Consent.exe is less than 6.0.6002.19116" test_ref="oval:org.mitre.oval:tst:122005"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Consent.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:122057"/>
              <criterion comment="Check if the version of Consent.exe is less than 6.0.6002.23415" test_ref="oval:org.mitre.oval:tst:122266"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Consent.exe is less than 6.1.7601.18493" test_ref="oval:org.mitre.oval:tst:122413"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Consent.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:122395"/>
              <criterion comment="Check if the version of Consent.exe is less than 6.1.7601.22708" test_ref="oval:org.mitre.oval:tst:122273"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Consent.exe is less than 6.3.9600.17198" test_ref="oval:org.mitre.oval:tst:122325"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of crypt32.dll is less than 5.131.3790.5362" test_ref="oval:org.mitre.oval:tst:122416"/>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Consent.exe is less than 6.2.9200.21139" test_ref="oval:org.mitre.oval:tst:122019"/>
              <criterion comment="Check if the version of Consent.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122075"/>
            </criteria>
            <criterion comment="Check if the version of Consent.exe is less than 6.2.9200.17022" test_ref="oval:org.mitre.oval:tst:121864"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26334" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4102 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4102"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4089, and CVE-2014-4091.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:57.475-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:32.770-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:41.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26322" version="3" class="vulnerability">
      <metadata>
        <title>Font Double-Fetch vulnerability - CVE-2014-1819 (MS14-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1819"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control access to objects associated with font files, which allows local users to gain privileges via a crafted file, aka "Font Double-Fetch Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:55:13.702-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:56.163-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:32.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2K3(all) and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5398" test_ref="oval:org.mitre.oval:tst:122069"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19150" test_ref="oval:org.mitre.oval:tst:121902"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23454" test_ref="oval:org.mitre.oval:tst:122185"/>
            </criteria>
            <criterion comment="Check if the version of Dxgkrnl.sys is less than 7.0.6002.19126" test_ref="oval:org.mitre.oval:tst:122360"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81004"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 7.0.6002.23427" test_ref="oval:org.mitre.oval:tst:122064"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18539" test_ref="oval:org.mitre.oval:tst:121806"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22750" test_ref="oval:org.mitre.oval:tst:122188"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.18510" test_ref="oval:org.mitre.oval:tst:122038"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version dxgkrnl.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81058"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.22720" test_ref="oval:org.mitre.oval:tst:122391"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17059" test_ref="oval:org.mitre.oval:tst:122363"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21178" test_ref="oval:org.mitre.oval:tst:122110"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.17031" test_ref="oval:org.mitre.oval:tst:122335"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.21148" test_ref="oval:org.mitre.oval:tst:122306"/>
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either vulnerable file">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17250" test_ref="oval:org.mitre.oval:tst:122384"/>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.3.9600.17210" test_ref="oval:org.mitre.oval:tst:122135"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26321" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4052 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4052"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:53.407-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:55.963-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:32.265-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26317" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to spoof web sites via a crafted HTML document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1451"/>
        <description>Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for remote attackers to spoof web sites via a crafted HTML document that triggers many HTTPS requests to an arbitrary host, followed by an HTTPS request to a trusted host and then an HTTP request to an untrusted host, a related issue to CVE-2013-1450.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:45.045-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:18.248-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:25.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26313" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4110 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4110"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:07.786-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:31.810-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:39.629-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26308" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1450"/>
        <description>Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS requests and then triggers an HTTP request to that host, as demonstrated by reading a Cookie header, aka MSRC 12096gd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:35.872-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:18.073-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:25.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26306" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2817 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2817"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:49.553-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:55.312-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:31.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26305" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2819 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2819"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:13.211-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:55.009-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:31.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26300" version="3" class="vulnerability">
      <metadata>
        <title>SharePoint Page Content Vulnerability (CVE-2014-2816) - MS14-050</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2816"/>
        <description>Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a Trojan horse app that executes a custom action in the context of the SharePoint extensibility model, aka "SharePoint Page Content Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:05:02.551-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:54.428-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:31.051-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Sharepoint Server or Foundation 2013">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
        </criteria>
        <criterion comment="Check if the version of wsssetup.dll is less than 15.0.4641.1000" test_ref="oval:org.mitre.oval:tst:121842"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26288" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4050 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4050"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-2825, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:34.431-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:53.911-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:30.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26242" version="3" class="vulnerability">
      <metadata>
        <title>LRPC ASLR Bypass Vulnerability - CVE-2014-0316 (MS14-047)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0316"/>
        <description>Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (memory consumption) and bypass the ASLR protection mechanism via a crafted client that sends messages with an invalid data view, aka "LRPC ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T09:59:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:58:49.332-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:49.498-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:29.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Rpcrt4.dll is less than 6.1.7601.18532" test_ref="oval:org.mitre.oval:tst:122167"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of rpcrt4.dll is greater than or equal 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:85227"/>
              <criterion comment="Check if the version of rpcrt4.dll is less than 6.1.7601.22743" test_ref="oval:org.mitre.oval:tst:122210"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Rpcrt4.dll is less than 6.2.9200.17037" test_ref="oval:org.mitre.oval:tst:121646"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of rpcrt4.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122334"/>
              <criterion comment="Check if the version of rpcrt4.dll is less than 6.2.9200.21154" test_ref="oval:org.mitre.oval:tst:122324"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Rpcrt4.dll is less than 6.3.9600.17216" test_ref="oval:org.mitre.oval:tst:122059"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26234" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-0325) - MS14-018</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0325" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0325"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site that triggers improper processing of CElement objects, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1751 and CVE-2014-1755.  NOTE: MS14-018 originally had a typo of CVE-2014-0235 for this.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-11T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-08-13T10:45:55.026-04:00">DRAFT</status_change>
            <status_change date="2014-09-01T04:03:10.788-04:00">INTERIM</status_change>
            <status_change date="2014-09-22T04:00:42.774-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="either OS">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
        </criteria>
        <criteria operator="OR" comment="GDR / LDR">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16545" test_ref="oval:org.mitre.oval:tst:113555"/>
          <criteria operator="AND" comment="LDR range">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20656" test_ref="oval:org.mitre.oval:tst:113735"/>
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
          </criteria>
        </criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26227" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2796 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2796"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:58.583-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:47.897-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:29.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26164" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4055 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4055"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:57.441-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:42.863-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:26.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26160" version="3" class="vulnerability">
      <metadata>
        <title>Windows OLE remote code execution vulnerability - CVE-2014-4114 (MS14-060)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4114"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T18:05:09.984-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:06.437-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:09.529-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.0.6002.19192" test_ref="oval:org.mitre.oval:tst:124892"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:125246"/>
              <criterion comment="Check if version of Packager.dll is less than 6.0.6002.23496" test_ref="oval:org.mitre.oval:tst:125013"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.1.7601.18601" test_ref="oval:org.mitre.oval:tst:125012"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:125217"/>
              <criterion comment="Check if version of Packager.dll is less than 6.1.7601.22809" test_ref="oval:org.mitre.oval:tst:125084"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.21237" test_ref="oval:org.mitre.oval:tst:125102"/>
              <criterion comment="Check if the version of Packager.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:124862"/>
            </criteria>
            <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.17121" test_ref="oval:org.mitre.oval:tst:125199"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of packager.dll is less than 6.3.9600.17341" test_ref="oval:org.mitre.oval:tst:124841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26158" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2825 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2825"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:05.620-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:42.656-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:26.535-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26136" version="3" class="vulnerability">
      <metadata>
        <title>Windows kernel pool allocation vulnerability - CVE-2014-4064 (MS14-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4064" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4064"/>
        <description>The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly handle use of the paged kernel pool for allocation of uninitialized memory, which allows local users to obtain sensitive information about kernel addresses via a crafted application, aka "Windows Kernel Pool Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:55:10.799-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:38.941-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:25.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19150" test_ref="oval:org.mitre.oval:tst:121902"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23454" test_ref="oval:org.mitre.oval:tst:122185"/>
            </criteria>
            <criterion comment="Check if the version of Dxgkrnl.sys is less than 7.0.6002.19126" test_ref="oval:org.mitre.oval:tst:122360"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81004"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 7.0.6002.23427" test_ref="oval:org.mitre.oval:tst:122064"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18539" test_ref="oval:org.mitre.oval:tst:121806"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22750" test_ref="oval:org.mitre.oval:tst:122188"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.18510" test_ref="oval:org.mitre.oval:tst:122038"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version dxgkrnl.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81058"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.22720" test_ref="oval:org.mitre.oval:tst:122391"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17059" test_ref="oval:org.mitre.oval:tst:122363"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21178" test_ref="oval:org.mitre.oval:tst:122110"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.17031" test_ref="oval:org.mitre.oval:tst:122335"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.21148" test_ref="oval:org.mitre.oval:tst:122306"/>
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either vulnerable file">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17250" test_ref="oval:org.mitre.oval:tst:122384"/>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.3.9600.17210" test_ref="oval:org.mitre.oval:tst:122135"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26130" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4091 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4091"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4089, and CVE-2014-4102.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:24.370-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:25.269-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:31.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26127" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4067 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4067" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4067"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, and CVE-2014-4055.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:35.636-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:38.728-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:24.957-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26121" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2826 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2826" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2826"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2827, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:45.677-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:38.151-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:24.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26120" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4063 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4063"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2826, and CVE-2014-2827.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:42.605-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:37.885-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:24.251-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26109" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2827 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2827" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2827"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2826, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:56.365-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:37.195-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:23.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26092" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4051 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4051"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2784.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:01.531-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:35.861-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:23.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26084" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4094 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4094"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:47.296-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:22.648-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:28.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26073" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4057 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4057"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2811, CVE-2014-2822, and CVE-2014-2823.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:39.369-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:34.153-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:21.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26043" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2824 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2824"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:33.119-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:31.814-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:21.582-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26040" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4085 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4085"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:49.873-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:21.321-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:24.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26009" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4084 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4084"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4093.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:44.596-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:21.113-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:23.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26001" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2811 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2811"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2822, CVE-2014-2823, and CVE-2014-4057.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:59.428-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:28.774-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:20.871-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25997" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2820 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2820"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2826, CVE-2014-2827, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:08.185-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:26.792-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:20.474-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25962" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2808 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2808"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:37.512-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:25.896-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:20.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25954" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2823 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2823"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2811, CVE-2014-2822, and CVE-2014-4057.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:36.453-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:24.595-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:19.830-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / 2k8 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25633" version="5" class="vulnerability">
      <metadata>
        <title>Arbitrary code executing via unknown vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1346"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:36.855-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:12.433-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:13.514-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25633 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:44.917-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:25.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16722" test_ref="oval:org.mitre.oval:tst:42403"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
            <criterion comment="Mshtml.dll version is less than 8.0.7600.20861" test_ref="oval:org.mitre.oval:tst:42393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25219" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2801 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2801"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:52.709-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:53.114-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25219 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:59.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25213" version="5" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability - CVE-2014-2781 (MS14-039)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2781"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different integrity levels, which allows attackers to bypass intended access restrictions by leveraging control over a low-integrity process to launch the On-Screen Keyboard (OSK) and then upload a crafted application, aka "On-Screen Keyboard Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:50:34.190-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:52.952-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:30.129-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19119" test_ref="oval:org.mitre.oval:tst:115705"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23420" test_ref="oval:org.mitre.oval:tst:115407"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18512" test_ref="oval:org.mitre.oval:tst:115070"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22722" test_ref="oval:org.mitre.oval:tst:115618"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17025" test_ref="oval:org.mitre.oval:tst:115552"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.21142" test_ref="oval:org.mitre.oval:tst:115273"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Check for with update and without update">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.16671" test_ref="oval:org.mitre.oval:tst:115570"/>
            <criteria operator="AND" comment="kb2973201 and kb2919355">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.3.9600.17031" test_ref="oval:org.mitre.oval:tst:115567"/>
              <criterion comment="Check if the version of Win32k.sys is less than 6.3.9600.17200" test_ref="oval:org.mitre.oval:tst:115441"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25208" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2802 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2802" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2802"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2787, CVE-2014-2790, and CVE-2014-2806.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:25.643-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:52.718-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25208 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:58.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25207" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2800 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2800"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2807 and CVE-2014-2809.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:14.917-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:52.441-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25207 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:58.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25190" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2786 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2786"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2792 and CVE-2014-2813.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:54.466-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:52.043-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25190 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:57.946-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25184" version="5" class="vulnerability">
      <metadata>
        <title>Service Bus Denial of Service Vulnerability - CVE-2014-2814 (MS14-042)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Service Bus 1.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2814"/>
        <description>Microsoft Service Bus 1.1 on Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (AMQP messaging outage) via crafted AMQP messages, aka "Service Bus Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T11:54:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:54:52.877-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:51.944-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:27.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Service Bus 1.1 is installed" definition_ref="oval:org.mitre.oval:def:24926"/>
        <criterion comment="Check if the version of Microsoft.ServiceBus.dll is less than 2.1.40512.2" test_ref="oval:org.mitre.oval:tst:115300"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24926" version="3" class="inventory">
      <metadata>
        <title>Microsoft Service Bus 1.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Service Bus 1.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:service_bus:1.1"/>
        <description>Microsoft Service Bus 1.1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T11:54:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:54:52.836-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:39.303-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:56.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Server Bus 1.1 is installed" test_ref="oval:org.mitre.oval:tst:114968"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25182" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2807 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2807"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2800 and CVE-2014-2809.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:48:00.406-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:51.671-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25182 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:57.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25165" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2797 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2797"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:20.446-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:51.382-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25165 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:56.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25143" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2804 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2804" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2804"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2798.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:50.184-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:50.965-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25143 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:54.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25112" version="5" class="vulnerability">
      <metadata>
        <title>DirectShow Elevation of Privilege Vulnerability - CVE-2014-2780 (MS14-041)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2780"/>
        <description>DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges by leveraging control over a low-integrity process to execute a crafted application, aka "DirectShow Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T12:04:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:53:04.839-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:49.397-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:15.727-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.19118" test_ref="oval:org.mitre.oval:tst:115438"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.6002.23000" test_ref="oval:org.mitre.oval:tst:81807"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.23418" test_ref="oval:org.mitre.oval:tst:115437"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.18501" test_ref="oval:org.mitre.oval:tst:115716"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.7601.22000" test_ref="oval:org.mitre.oval:tst:81771"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.22716" test_ref="oval:org.mitre.oval:tst:115674"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.17023" test_ref="oval:org.mitre.oval:tst:115629"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.9200.20000" test_ref="oval:org.mitre.oval:tst:81492"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.21140" test_ref="oval:org.mitre.oval:tst:115619"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable version">
            <criteria operator="AND" comment="kb2972280 and kb2919355">
              <criterion comment="Check if the version of qedit.dll is less than 6.6.9600.17200" test_ref="oval:org.mitre.oval:tst:115516"/>
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.9600.17031" test_ref="oval:org.mitre.oval:tst:115712"/>
            </criteria>
            <criterion comment="Check if the version of qedit.dll is less than 6.6.9600.16672" test_ref="oval:org.mitre.oval:tst:115285"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25105" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2803 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2803"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:45.037-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:48.984-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25105 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:54.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25096" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-1765 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1765"/>
        <description>Multiple use-after-free vulnerabilities in Microsoft Internet Explorer 6 through 11 allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:42.536-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:48.622-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25096 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:53.618-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25063" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2787 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2787" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2787"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2790, CVE-2014-2802, and CVE-2014-2806.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:48:01.320-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:48.115-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25063 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:53.200-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25048" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2791 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2791"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:18.571-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:47.983-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25048 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:52.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25034" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2809 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2809"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2800 and CVE-2014-2807.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:28.449-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:47.544-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25034 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:52.413-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25024" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1805) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1805" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1805"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:40.378-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:33.444-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:47.058-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25024 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:55.111-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:52.029-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25012" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-1763 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1763"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:16.755-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:46.638-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25012 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:51.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24999" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1792) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1792" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1792"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1781, CVE-2014-1804, and CVE-2014-2770.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:26.319-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:33.040-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:46.361-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24999 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:08.794-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:51.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24996" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2755) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2755"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:56.150-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:32.905-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:46.200-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24996 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:11.329-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:50.980-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24991" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2758) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2758"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:12.077-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:32.682-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:45.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24991 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:55.525-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:50.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24990" version="6" class="vulnerability">
      <metadata>
        <title>Extended Validation (EV) Certificate Security Feature Bypass Vulnerability - CVE-2014-2783 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2783"/>
        <description>Microsoft Internet Explorer 7 through 11 does not prevent use of wildcard EV SSL certificates, which might allow remote attackers to spoof a trust level by leveraging improper issuance of a wildcard certificate by a recognized Certification Authority, aka "Extended Validation (EV) Certificate Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:33.936-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:45.703-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24990 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:50.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24986" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1772) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1772"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:57.437-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:32.461-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:45.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24986 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:15.739-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:49.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24976" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1766) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1766"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet Explorer exploit payload, but this ID is not for a kernel vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:14.721-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:32.109-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:44.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24976 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:11.078-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:49.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24974" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Information Disclosure Vulnerability (CVE-2014-1777) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1777"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:40.789-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:31.743-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:44.588-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24974 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:10.373-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:48.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24972" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2771) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2771"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, and CVE-2014-2769.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:42.555-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:31.564-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:44.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24972 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:10.152-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:48.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24967" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2813 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2813"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2786 and CVE-2014-2792.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:23.313-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:43.813-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24967 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:48.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24965" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2014-1764) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1764"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:39.440-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:31.098-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:43.560-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24965 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:10.727-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:47.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24963" version="6" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft XML Core Services could allow information disclosure (CVE-2014-1816) - MS14-033</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft XML Core Services 3</product>
          <product>Microsoft XML Core Services 6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1816"/>
        <description>Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:35:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:04:13.279-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19706 - comment has been updated from &quot;less than&quot; to &quot;greater than or equal&quot;" date="2014-06-20T11:02:00.031-04:00">
              <contributor organization="SecPod Technologies">Saurabh Kumar</contributor>
            </modified>
            <status_change date="2014-07-07T04:01:30.809-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:42.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24963 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:16.608-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:47.077-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2003/version">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.1055.0" test_ref="oval:org.mitre.oval:tst:114554"/>
        </criteria>
        <criteria operator="AND" comment="2003/version">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Msxml6.dll is less than 6.20.2017.0" test_ref="oval:org.mitre.oval:tst:114851"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/versions/Core services 3.0">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.5008.0" test_ref="oval:org.mitre.oval:tst:114914"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/versions/Core services 6.0">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of Msxml6.dll is less than 6.20.5007.0" test_ref="oval:org.mitre.oval:tst:114749"/>
        </criteria>
        <criteria operator="AND" comment="win7/2008 r2/versions/Core services 3.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.18431" test_ref="oval:org.mitre.oval:tst:114835"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.22640" test_ref="oval:org.mitre.oval:tst:114525"/>
              <criterion comment="Check if version of Msxml3.dll is greater than or equal to 8.110.7601.22000" test_ref="oval:org.mitre.oval:tst:79072"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
        </criteria>
        <criteria operator="AND" comment="win7/2008 r2/versions/Core services 6.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml6.dll is less than 6.30.7601.18431" test_ref="oval:org.mitre.oval:tst:114941"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml6.dll is less than 6.30.7601.22640" test_ref="oval:org.mitre.oval:tst:114376"/>
              <criterion comment="Check if version of Msxml6.dll is greater than or equal to 6.30.7601.22000" test_ref="oval:org.mitre.oval:tst:79900"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
        </criteria>
        <criteria operator="AND" comment="win8/2012/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.16863" test_ref="oval:org.mitre.oval:tst:114488"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.20982" test_ref="oval:org.mitre.oval:tst:114321"/>
              <criterion comment="Check if the version of msxml3.dll is greater than or equal to 8.110.9200.20000" test_ref="oval:org.mitre.oval:tst:80548"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8.1/2012 r2/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9600.16663" test_ref="oval:org.mitre.oval:tst:114638"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:454" version="3" class="inventory">
      <metadata>
        <title>Microsoft XML Core Services 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services 6</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:xml_core_services:6"/>
        <description>Microsoft XML Core Services 6 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:42.283-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:51.747-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:454 - products added to inventories" date="2015-04-17T09:39:00.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:41:23.422-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 6 is installed." test_ref="oval:org.mitre.oval:tst:182"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24959" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2760) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2760"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:12.911-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:30.660-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:42.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24959 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.849-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:46.774-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24946" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1789) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1789" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1789"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1790.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:25.837-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:30.524-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:41.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24946 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:06.352-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:46.496-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24945" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1800) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1800"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:20.912-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:29.558-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:41.258-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24945 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.902-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:45.863-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24943" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2772) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2772"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:57.093-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:29.405-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:40.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24943 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:50.101-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:45.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24937" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1781) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1781"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1792, CVE-2014-1804, and CVE-2014-2770.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:32.046-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:29.054-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:40.581-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24937 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:11.529-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:45.275-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24935" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2754) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2754"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1774 and CVE-2014-1788.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:27.392-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:28.879-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:40.426-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24935 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.321-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:44.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24934" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2776) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2776"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, and CVE-2014-2772.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:41.285-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:28.719-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:40.242-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24934 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:11.712-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:44.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24933" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2759) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2759" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2759"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:38.413-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:28.440-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:39.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24933 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.011-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:44.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24928" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer (CVE-2014-1779) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1796" ref_url="http://www.scaprepo.com/view.jsp?id=CVE-2014-1796"/>
        <description>Microsoft Internet Explorer 6 and 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:54:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:24.630-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:28.058-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:39.412-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24928 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:09.117-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:43.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24925" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1780) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1780"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:06.419-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:27.899-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:39.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24925 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.729-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:43.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24921" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2757) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2757" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2757"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-1803.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:53.859-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:27.575-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:38.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24921 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:05.622-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:42.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24915" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2790 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2790"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2787, CVE-2014-2802, and CVE-2014-2806.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:21.349-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:37.782-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24915 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:42.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24913" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1773) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1773"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:54.299-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:27.277-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:37.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24913 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:54.070-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:41.932-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24912" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0282) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0282"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:36.396-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.867-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:37.066-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24912 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:12.777-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:41.418-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24910" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2792 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2792" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2792"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2786 and CVE-2014-2813.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:37.125-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:36.789-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24910 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:40.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24903" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in TCP Protocol could allow denial of service - CVE-2014-1811 (MS14-031)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1811"/>
        <description>The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (non-paged pool memory consumption and system hang) via malformed data in the Options field of a TCP header, aka "TCP Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T15:41:45">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:12:24.570-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.561-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:36.307-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Vista / Server 2008 and vulnerable file version">
          <criteria operator="OR" comment="Win Vista/ Server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.19080" test_ref="oval:org.mitre.oval:tst:114852"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80825"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.23370" test_ref="oval:org.mitre.oval:tst:114891"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 / 2008 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Windows 7 / 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.18438" test_ref="oval:org.mitre.oval:tst:114905"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81171"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.22648" test_ref="oval:org.mitre.oval:tst:114908"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.16886" test_ref="oval:org.mitre.oval:tst:114909"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114778"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.21005" test_ref="oval:org.mitre.oval:tst:114708"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/ 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criteria operator="AND" comment="kb2957189 and kb2919355">
              <criterion comment="Check if the version of tcpip.sys is less than 6.3.9600.17088" test_ref="oval:org.mitre.oval:tst:114093"/>
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.3.9600.17039" test_ref="oval:org.mitre.oval:tst:114935"/>
            </criteria>
            <criterion comment="Check if the version of tcpip.sys is less than 6.3.9600.16660" test_ref="oval:org.mitre.oval:tst:114088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24902" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2756) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2756" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2756"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:58.826-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.407-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:36.084-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24902 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:06.619-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:40.247-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24901" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2766) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2766"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:23:05.034-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.164-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:35.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24901 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:11.923-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:39.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24899" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1779) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1779"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:23:03.059-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.884-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:35.532-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24899 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.402-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:39.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24898" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2765) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2765"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:49.518-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.645-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:35.185-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24898 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:16.217-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:38.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24896" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1783) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1783"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:02.335-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.421-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:34.787-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24896 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:12.293-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:38.307-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24895" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2798 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2798"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2804.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:47.723-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:34.528-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24895 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:37.768-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24890" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1790) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1790"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1789.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:21.951-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.213-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:34.361-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24890 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:55.353-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:37.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24882" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1771) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1771"/>
        <description>SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:43.805-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:24.315-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:33.185-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24882 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:20.131-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:36.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24875" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1802) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1802" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1802"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:46.825-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:24.007-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:32.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24875 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.574-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:36.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24850" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1785) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1785" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1785"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:22.772-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:23.709-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:32.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24850 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:23.665-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:36.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24835" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1782) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1782"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:46.755-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:22.541-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:31.926-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24835 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:23.114-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:35.981-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24825" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2764) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2764"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:21.673-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.897-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:31.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24825 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.154-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:35.753-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24823" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1762) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1762"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:50.922-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.600-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:30.999-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24823 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:17.887-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:35.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24815" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1784) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1784"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:45.812-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.375-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:30.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24815 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.652-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:34.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24810" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1775) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1775"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:33.451-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.002-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:30.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24810 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.518-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:34.283-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24787" version="3" class="vulnerability">
      <metadata>
        <title>Web Applications Page Content Vulnerability (CVE-2014-1813) - MS14-022</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1813"/>
        <description>Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applications Page Content Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:06.381-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:16.303-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:20.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="office web apps sp1/sp2">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19186"/>
        </criteria>
        <criterion comment="Check if the version of SWORD.DLL is less than 14.0.7123.5000" test_ref="oval:org.mitre.oval:tst:114167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24776" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1785) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1786"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:30.455-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:19.840-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:27.930-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24776 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:18.415-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:33.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24749" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1788) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1788" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1788"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1774 and CVE-2014-2754.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:33.180-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:19.211-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:27.550-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24749 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:23.530-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:33.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24744" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2789 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2789" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2789"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2795, CVE-2014-2798, and CVE-2014-2804.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:31.066-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:27.187-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24744 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:32.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24704" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory corruption vulnerability (CVE-2014-1776) - MS14-021</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1776"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014.  NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-07T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-07T13:42:59.565-04:00">DRAFT</status_change>
            <status_change date="2014-05-26T04:06:29.300-04:00">INTERIM</status_change>
            <status_change date="2014-06-16T04:00:14.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24704 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:11.571-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:43.990-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6550" test_ref="oval:org.mitre.oval:tst:113946"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5328" test_ref="oval:org.mitre.oval:tst:113858"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21383" test_ref="oval:org.mitre.oval:tst:113947"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19087" test_ref="oval:org.mitre.oval:tst:114090"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23377" test_ref="oval:org.mitre.oval:tst:113855"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19529" test_ref="oval:org.mitre.oval:tst:113843"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23588" test_ref="oval:org.mitre.oval:tst:114020"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18446" test_ref="oval:org.mitre.oval:tst:113410"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22657" test_ref="oval:org.mitre.oval:tst:113850"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23588" test_ref="oval:org.mitre.oval:tst:114020"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16546" test_ref="oval:org.mitre.oval:tst:113116"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20657" test_ref="oval:org.mitre.oval:tst:113966"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16897" test_ref="oval:org.mitre.oval:tst:114060"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21024" test_ref="oval:org.mitre.oval:tst:113720"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either OS">
            <criteria operator="AND" comment="7/2008R2/versions">
              <criteria operator="OR" comment="7/2008R2">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16661" test_ref="oval:org.mitre.oval:tst:113948"/>
                <criteria operator="AND" comment="kb2964358 and kb2929437">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17105" test_ref="oval:org.mitre.oval:tst:114028"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="8.1/2012R2/versions">
              <criteria operator="OR" comment="8.1/2012R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16661" test_ref="oval:org.mitre.oval:tst:113948"/>
                <criteria operator="AND" comment="kb2964358 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17105" test_ref="oval:org.mitre.oval:tst:114028"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24690" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2777) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2777"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-1778.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:10.064-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:18.531-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:26.678-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24690 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.132-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:32.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24687" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1774) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1774"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1788 and CVE-2014-2754.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:15.952-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:18.367-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:26.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24687 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.900-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:31.816-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24654" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-1815) - MS14-029</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1815"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0310.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:58:00.200-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:20.501-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:36.322-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24654 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:09.713-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:35.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6/2003/versions">
          <criteria operator="OR" comment="2003">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5330" test_ref="oval:org.mitre.oval:tst:114173"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="2003/vista/2008/">
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21385" test_ref="oval:org.mitre.oval:tst:113959"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19089" test_ref="oval:org.mitre.oval:tst:113982"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23380" test_ref="oval:org.mitre.oval:tst:113848"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19531" test_ref="oval:org.mitre.oval:tst:114050"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18448" test_ref="oval:org.mitre.oval:tst:113593"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22659" test_ref="oval:org.mitre.oval:tst:114134"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16553" test_ref="oval:org.mitre.oval:tst:114230"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20664" test_ref="oval:org.mitre.oval:tst:113967"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16899" test_ref="oval:org.mitre.oval:tst:114075"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21026" test_ref="oval:org.mitre.oval:tst:114122"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either OS">
            <criteria operator="AND" comment="7/2008R2/versions">
              <criteria operator="OR" comment="7/2008R2">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2929437">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="8.1/2012R2/versions">
              <criteria operator="OR" comment="8.1/2012R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24648" version="5" class="vulnerability">
      <metadata>
        <title>Vulnerability in .NET Framework could allow elevation of privilege - MS14-026</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1806"/>
        <description>The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T15:16:57.075+05:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:53:00.420-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:19.883-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:35.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24648 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:12.295-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:35.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of system.runtime.remoting.dll is less than 1.1.4322.2506" test_ref="oval:org.mitre.oval:tst:113757"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.3659" test_ref="oval:org.mitre.oval:tst:113488"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7055" test_ref="oval:org.mitre.oval:tst:114151"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.4252" test_ref="oval:org.mitre.oval:tst:114129"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7057" test_ref="oval:org.mitre.oval:tst:114087"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of the system.runtime.remoting.dll is less than 2.0.50727.6416" test_ref="oval:org.mitre.oval:tst:113918"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7055" test_ref="oval:org.mitre.oval:tst:114151"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8003" test_ref="oval:org.mitre.oval:tst:114169"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8606" test_ref="oval:org.mitre.oval:tst:113903"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.5483" test_ref="oval:org.mitre.oval:tst:114215"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7057" test_ref="oval:org.mitre.oval:tst:114087"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.1023" test_ref="oval:org.mitre.oval:tst:114080"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.2036" test_ref="oval:org.mitre.oval:tst:114124"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:113636"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34108" test_ref="oval:org.mitre.oval:tst:114202"/>
            <criteria operator="AND" comment="ldr range for system.wen.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36106" test_ref="oval:org.mitre.oval:tst:114073"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34107" test_ref="oval:org.mitre.oval:tst:113283"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36105" test_ref="oval:org.mitre.oval:tst:114065"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / Win 8.1 / Server 2012 R2">
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34107" test_ref="oval:org.mitre.oval:tst:113283"/>
            <criteria operator="AND" comment="ldr range for mscorlib.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36115" test_ref="oval:org.mitre.oval:tst:114125"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24629" version="9" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-0235) - MS14-018</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0235"/>
        <description>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2014-0325, CVE-2014-3538.  Reason: This candidate is a duplicate of CVE-2014-0325 and/or CVE-2014-3538.  A typo caused the wrong ID to be used.  Notes: All CVE users should reference CVE-2014-0325 instead of this candidate for the issue in the Internet Explorer product, and should reference CVE-2014-3538 instead of this candidate for the issue in the file product.  All references and descriptions in this candidate have been removed to prevent accidental usage.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-04-10T14:44:13.139-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:39.252-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:26.685-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24629 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:10.624-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:34.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="either 2k8, 2k8 R2, Win 7 / Vista">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
        </criteria>
        <criteria operator="OR" comment="GDR / LDR">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16545" test_ref="oval:org.mitre.oval:tst:113555"/>
          <criteria operator="AND" comment="LDR range">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20656" test_ref="oval:org.mitre.oval:tst:113735"/>
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
          </criteria>
        </criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24620" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1769) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1769"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:28.319-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:17.338-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:25.207-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24620 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:23.795-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:31.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24618" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2441"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-04-18T14:38:40.749-04:00">DRAFT</status_change>
            <status_change date="2014-05-05T04:00:24.278-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:28.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.30" test_ref="oval:org.mitre.oval:tst:113796"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.22" test_ref="oval:org.mitre.oval:tst:113462"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.8" test_ref="oval:org.mitre.oval:tst:113616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24600" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1804) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1804" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1804"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1781, CVE-2014-1792, and CVE-2014-2770.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:27.378-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:17.084-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:24.972-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24600 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:54.239-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:31.029-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24592" version="5" class="vulnerability">
      <metadata>
        <title>Ancillary Function Driver Elevation of Privilege Vulnerability - CVE-2014-1767 (MS14-040)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1767"/>
        <description>Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:51:49.746-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:24.303-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:33.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 x86,x64/ia64 SP2">
          <criteria operator="OR" comment="Windows Server 2003 x86,x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <criterion comment="Check if the version of Afd.sys is less than 5.2.3790.5358" test_ref="oval:org.mitre.oval:tst:115663"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86,x64 SP2, Server 2008 x86,x64/ia64 SP2">
          <criteria operator="OR" comment="Windows Vista x86,x64 SP2, Server 2008 x86,x64/ia64">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Afd.sys is less than 6.0.6002.19115" test_ref="oval:org.mitre.oval:tst:115682"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of afd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87004"/>
              <criterion comment="Check if the version of Afd.sys is less than 6.0.6002.23414" test_ref="oval:org.mitre.oval:tst:115447"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x64 SP1, Server 2008 R2 x64/ia64 SP1">
          <criteria operator="OR" comment="Microsoft Windows 7 x86,x64 SP1, Server 2008 R2 x64/ia64 SP1">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Afd.sys is less than 6.1.7601.18489" test_ref="oval:org.mitre.oval:tst:115701"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of afd.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42554"/>
              <criterion comment="Check if the version of Afd.sys is less than 6.1.7601.22705" test_ref="oval:org.mitre.oval:tst:115620"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Afd.sys is less than 6.2.9200.17014" test_ref="oval:org.mitre.oval:tst:114833"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Afd.sys is less than 6.2.9200.21133" test_ref="oval:org.mitre.oval:tst:115622"/>
              <criterion comment="Check if the version of afd.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:87102"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Afd.sys is less than 6.3.9600.16668" test_ref="oval:org.mitre.oval:tst:115522"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Afd.sys is less than 6.3.9600.17194" test_ref="oval:org.mitre.oval:tst:115534"/>
              <criterion comment="Check if the version of Afd.sys is greater than or equal to 6.3.9600.17088" test_ref="oval:org.mitre.oval:tst:115711"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24590" version="7" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-1755) - MS14-018</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1755"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0235 and CVE-2014-1751.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-04-10T14:44:06.334-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:39.151-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:26.118-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24590 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:09.180-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:33.233-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="either 2k8, 2k8 R2, Win 7 / Vista">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
        </criteria>
        <criteria operator="OR" comment="GDR / LDR">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16545" test_ref="oval:org.mitre.oval:tst:113555"/>
          <criteria operator="AND" comment="LDR range">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20656" test_ref="oval:org.mitre.oval:tst:113735"/>
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
          </criteria>
        </criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24580" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1803) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1803"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:20.327-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:16.363-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:23.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24580 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:16.327-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:30.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24572" version="3" class="vulnerability">
      <metadata>
        <title>Windows Shell File Association Vulnerability - CVE-2014-1807 (MS14-027)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1807"/>
        <description>The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly implement file associations, which allows local users to gain privileges via a crafted application, as exploited in the wild in May 2014, aka "Windows Shell File Association Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T19:28:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:54:32.634-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:00.973-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:24.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2K3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of shlwapi.dll is less than 6.0.3790.5318" test_ref="oval:org.mitre.oval:tst:114095"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2K8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.19070" test_ref="oval:org.mitre.oval:tst:114063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113981"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.23360" test_ref="oval:org.mitre.oval:tst:113937"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="&quot;Windows 7 / 2008 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.18429" test_ref="oval:org.mitre.oval:tst:113790"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113444"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.22639" test_ref="oval:org.mitre.oval:tst:114152"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / Server 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.16882" test_ref="oval:org.mitre.oval:tst:114153"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:114092"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114163"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.3.9600.17083" test_ref="oval:org.mitre.oval:tst:113863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24566" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1794) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1794"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:55.166-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:16.230-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:22.952-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24566 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.752-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:29.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24531" version="7" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-1760) - MS14-018</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1760"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-04-10T14:44:07.163-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:38.553-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:19.703-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24531 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:08.433-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:32.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="either Win 8.1, 2k8 R2, Win 7 / 2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16659" test_ref="oval:org.mitre.oval:tst:113819"/>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24514" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2761) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2761"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:05.192-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:15.734-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:21.783-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24514 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.016-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:29.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24506" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1778) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1778"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:52.275-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:15.482-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:21.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24506 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.193-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:28.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24496" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2795 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2795" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2795"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2798, and CVE-2014-2804.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:57.553-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:20.727-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24496 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:28.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24480" version="3" class="vulnerability">
      <metadata>
        <title>SharePoint XSS Vulnerability (CVE-2014-1754) - MS14-022</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
          <product>Microsoft Office Web Apps Server 2013</product>
          <product>Microsoft SharePoint Server 2013 Client Components SDK</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1754"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:08.488-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:11.888-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:15.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="foundation 2013/version">
          <criterion comment="Check if the version of Microsoft.Office.Server.Msg.dll is less than 15.0.4514.1000" test_ref="oval:org.mitre.oval:tst:114603"/>
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
            <extend_definition comment="Microsoft SharePoint Server 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24462"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2013/version">
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24685"/>
          </criteria>
          <criteria operator="OR" comment="either versions">
            <criterion comment="Check if the version of wsssetup.dll is less than 15.0.4615.1000" test_ref="oval:org.mitre.oval:tst:113960"/>
            <criterion comment="Check if the version of wsetupui.dll is less than 15.0.4561.1000" test_ref="oval:org.mitre.oval:tst:114600"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="web apps server 2013/version">
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft Office Web Apps Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:22312"/>
            <extend_definition comment="Microsoft Office Web Apps Server 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24530"/>
          </criteria>
          <criterion comment="Check if the version of msoserver.dll is less than 15.0.4615.1000" test_ref="oval:org.mitre.oval:tst:114430"/>
        </criteria>
        <criteria operator="AND" comment="SharePoint Server 2013 Client Components SDK/version">
          <extend_definition comment="Microsoft SharePoint Server 2013 Client Components SDK is installed" definition_ref="oval:org.mitre.oval:def:24752"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.client.dll is less than 15.0.4609.1000" test_ref="oval:org.mitre.oval:tst:114066"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24752" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 Client Components SDK is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft SharePoint Server 2013 Client Components SDK</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server_client_components_sdk:2013"/>
        <description>Microsoft SharePoint Server 2013 Client Components SDK is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T16:15:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:05.214-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:15.775-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:19.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft SharePoint Server 2013 Client Components SDK is installed" test_ref="oval:org.mitre.oval:tst:114587"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24685" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2013:sp1"/>
        <description>Microsoft SharePoint Foundation 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:04.107-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:13.760-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:18.247-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39142 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.534-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:43.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Sharepoint server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114158"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24530" version="6" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps Server 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Office Web Apps Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2013:sp1"/>
        <description>Microsoft Office Web Apps Server 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:04.569-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39205 - regular expression fixes" date="2014-06-10T14:50:00.707-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-30T04:10:22.150-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:22.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39205 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:35.894-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:32.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Web Apps Server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114300"/>
        <extend_definition comment="Microsoft Office Web Apps Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:22312"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24462" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2013:sp1"/>
        <description>Microsoft SharePoint Server 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:03.977-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:11.763-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:14.552-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39142 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.577-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:31.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Sharepoint server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114158"/>
        <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24478" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2773) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2773"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2768.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:24.867-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:14.875-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:20.193-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24478 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:15.154-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:27.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24476" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-0310) - MS14-029</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0310"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1815.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:58:03.253-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:44.040-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:20.289-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24476 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:11.241-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:31.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6/2003/versions">
          <criteria operator="OR" comment="2003">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5330" test_ref="oval:org.mitre.oval:tst:114173"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="2003/vista/2008/">
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21385" test_ref="oval:org.mitre.oval:tst:113959"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19089" test_ref="oval:org.mitre.oval:tst:113982"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23380" test_ref="oval:org.mitre.oval:tst:113848"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19531" test_ref="oval:org.mitre.oval:tst:114050"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18448" test_ref="oval:org.mitre.oval:tst:113593"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22659" test_ref="oval:org.mitre.oval:tst:114134"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16553" test_ref="oval:org.mitre.oval:tst:114230"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20664" test_ref="oval:org.mitre.oval:tst:113967"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16899" test_ref="oval:org.mitre.oval:tst:114075"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21026" test_ref="oval:org.mitre.oval:tst:114122"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either OS">
            <criteria operator="AND" comment="7/2008R2/versions">
              <criteria operator="OR" comment="7/2008R2">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2929437">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="8.1/2012R2/versions">
              <criteria operator="OR" comment="8.1/2012R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24465" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2763) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2763"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:07.619-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:14.685-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:19.791-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24465 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.572-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:27.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24442" version="6" class="vulnerability">
      <metadata>
        <title>Windows file handling vulnerability - CVE-2014-0315 (MS14-019)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0315"/>
        <description>Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse cmd.exe file in the current working directory, as demonstrated by a directory that contains a .bat or .cmd file, aka "Windows File Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T12:04:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-04-10T14:51:40.124-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:20161 - MS14-019 for the month of Apr 2014" date="2014-04-10T14:44:00.532-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-04-28T04:07:36.006-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:15.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win XP X86 + vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of kernel32.dll is less than 5.1.2600.6532" test_ref="oval:org.mitre.oval:tst:113820"/>
        </criteria>
        <criteria operator="AND" comment="XP X64 + vulnerable file version">
          <criteria operator="OR" comment="XP X64 / 2k3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of kernel32.dll is less than 5.2.3790.5295" test_ref="oval:org.mitre.oval:tst:113436"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.19034" test_ref="oval:org.mitre.oval:tst:113783"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113560"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.23323" test_ref="oval:org.mitre.oval:tst:113872"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 SP1 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.18409" test_ref="oval:org.mitre.oval:tst:113150"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113836"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.22616" test_ref="oval:org.mitre.oval:tst:113597"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of kernel32.dll is less than 6.2.9200.16815" test_ref="oval:org.mitre.oval:tst:113503"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:112923"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.2.9200.20935" test_ref="oval:org.mitre.oval:tst:113794"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of kernel32.dll is less than 6.3.9600.16656" test_ref="oval:org.mitre.oval:tst:113804"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24381" version="7" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-1753) - MS14-018</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1753"/>
        <description>Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-04-10T14:44:12.077-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:34.165-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:14.693-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24381 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:11.838-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:30.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="XP, 2k3, Vista or 2k8">
            <criteria operator="AND" comment="2k8 or Vista and vulnerable file version">
              <criteria operator="OR" comment="either OS">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="GDR / LDR">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19044" test_ref="oval:org.mitre.oval:tst:113734"/>
                <criteria operator="AND" comment="LDR Range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23333" test_ref="oval:org.mitre.oval:tst:113669"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="Either OS">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21376" test_ref="oval:org.mitre.oval:tst:112962"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="XP / 2k3 and vulnerable file version">
            <criteria operator="AND" comment="Win Xp (x86) and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6525" test_ref="oval:org.mitre.oval:tst:113743"/>
            </criteria>
            <criteria operator="AND" comment="Win XP (x64) or Win 2k3 and vulnerable file version">
              <criteria operator="OR" comment="Either OS">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5303" test_ref="oval:org.mitre.oval:tst:113550"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR / LDR">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16545" test_ref="oval:org.mitre.oval:tst:113555"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20656" test_ref="oval:org.mitre.oval:tst:113735"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="XP / 2k3 / Vista / 2k8 / Win 7 / R2 and vulnerable file versions">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23580" test_ref="oval:org.mitre.oval:tst:113520"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23580" test_ref="oval:org.mitre.oval:tst:113520"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19518" test_ref="oval:org.mitre.oval:tst:113446"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22609" test_ref="oval:org.mitre.oval:tst:113556"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18404" test_ref="oval:org.mitre.oval:tst:113854"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24372" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1797) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1797"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:23:00.130-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:12.252-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:18.473-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24372 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.889-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:26.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24328" version="3" class="vulnerability">
      <metadata>
        <title>Group Policy Preferences Password Elevation of Privilege Vulnerability - CVE-2014-1812 (MS14-025)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1812"/>
        <description>The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T13:00:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:51:25.813-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:34.612-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:07.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2k8/Vista and vulnerable file version">
          <criteria operator="OR" comment="2k8 / Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of gpme.dll is less than 6.0.6002.19047" test_ref="oval:org.mitre.oval:tst:114027"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of gpme.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:114197"/>
              <criterion comment="Check if the version of gpme.dll is less than 6.0.6002.23339" test_ref="oval:org.mitre.oval:tst:114149"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of gpme.dll is less than 6.1.7601.17514" test_ref="oval:org.mitre.oval:tst:113921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of gpme.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113430"/>
              <criterion comment="Check if the version of gpme.dll is less than 6.1.7601.22605" test_ref="oval:org.mitre.oval:tst:114131"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8/ 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criterion comment="Check if the version of gpme.dll is less than 6.2.9200.16384" test_ref="oval:org.mitre.oval:tst:113789"/>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 or Server 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/ 2k12">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of gppref.dll is less than 6.3.9600.16660" test_ref="oval:org.mitre.oval:tst:114190"/>
            <criteria operator="AND" comment="Check for version if KB2919355 is installed">
              <criterion comment="Check if the version of gppref.dll is greater than or equal to 6.3.9600.17039" test_ref="oval:org.mitre.oval:tst:114228"/>
              <criterion comment="Check if the version of gppref.dll is less than 6.3.9600.17041" test_ref="oval:org.mitre.oval:tst:114074"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24280" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2806 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2806"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2787, CVE-2014-2790, and CVE-2014-2802.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:17.602-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:17.788-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24280 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:26.445-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24252" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2775) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2775"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, and CVE-2014-2766.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:56.297-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:08.250-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:16.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24252 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:50.278-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:25.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24218" version="7" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-1751) - MS14-018</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1751"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0235 and CVE-2014-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-04-10T14:44:09.883-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:30.530-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:12.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24218 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:09.296-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:28.756-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="either 2k8, 2k8 R2, Win 7 / Vista">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
        </criteria>
        <criteria operator="OR" comment="GDR / LDR">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16545" test_ref="oval:org.mitre.oval:tst:113555"/>
          <criteria operator="AND" comment="LDR range">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20656" test_ref="oval:org.mitre.oval:tst:113735"/>
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
          </criteria>
        </criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24216" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2768) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2768" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2768"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2773.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:00.533-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:06.980-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:16.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24216 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:20.483-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:25.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24170" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1770) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1770"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:30.522-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:05.287-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:15.020-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24170 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:50.571-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:24.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24136" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2753) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2753"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:47.572-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:04.828-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:14.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24136 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:54.699-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:23.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / 2k8 R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2929437">
                <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
              <criteria operator="AND" comment="kb2957689 and kb2919355">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24120" version="5" class="vulnerability">
      <metadata>
        <title>Vulnerability in the VirtualBox component in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8 when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server (CVE-2014-0981)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0981"/>
        <description>VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption.  NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-04-04T10:24:42.126-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:37.090-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:33.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:113418"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.6" test_ref="oval:org.mitre.oval:tst:113364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24112" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2770) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2770"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1781, CVE-2014-1792, and CVE-2014-1804.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:17.391-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:02.655-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:13.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24112 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:50.863-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:23.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24093" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1799) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1799"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:36.174-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:02.181-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:13.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24093 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.291-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:22.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24027" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2769) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2769"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:48.022-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:01.192-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:12.065-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24027 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.408-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:22.275-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24026" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in the VirtualBox component in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8 when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server (CVE-2014-0983)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0983"/>
        <description>Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CR_VERTEXATTRIB1DARB_OPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CR_VERTEXATTRIB1FARB_OPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CR_VERTEXATTRIB1SARB_OPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CR_VERTEXATTRIB2DARB_OPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CR_VERTEXATTRIB2FARB_OPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CR_VERTEXATTRIB2SARB_OPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CR_VERTEXATTRIB3DARB_OPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CR_VERTEXATTRIB3FARB_OPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CR_VERTEXATTRIB3SARB_OPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CR_VERTEXATTRIB4DARB_OPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CR_VERTEXATTRIB4FARB_OPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CR_VERTEXATTRIB4SARB_OPCODE to the crServerDispatchVertexAttrib4sARB function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-04-04T10:24:41.750-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:34.902-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:30.503-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:113418"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.6" test_ref="oval:org.mitre.oval:tst:113364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24023" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1795) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1795" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1795"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:04.244-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:00.926-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:11.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24023 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:16.949-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:21.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24022" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2014-1791) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1791"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:45.359-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:00.540-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:10.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24022 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:56.247-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:19.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22660" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0322) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0322" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0322"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:44.741-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:37.266-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:30.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22660 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:09.043-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22652" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0297) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0297"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0308, CVE-2014-0312, and CVE-2014-0324.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:36.344-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:37.053-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:29.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22652 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:38.900-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.023-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22633" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Information Disclosure Vulnerability - CVE-2014-0323 (MS14-015)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0323"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (system hang) via a crafted application, aka "Win32k Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T11:06:05.764-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.877-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:29.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP (x86)+ vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6514" test_ref="oval:org.mitre.oval:tst:100494"/>
        </criteria>
        <criteria operator="AND" comment="XP X64/2K3(all) and vulnerable file version">
          <criteria operator="OR" comment="XP x64 / 2k3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5296" test_ref="oval:org.mitre.oval:tst:100886"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19036" test_ref="oval:org.mitre.oval:tst:100733"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23325" test_ref="oval:org.mitre.oval:tst:100089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18388" test_ref="oval:org.mitre.oval:tst:100894"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22592" test_ref="oval:org.mitre.oval:tst:100902"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16817" test_ref="oval:org.mitre.oval:tst:100579"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20937" test_ref="oval:org.mitre.oval:tst:100323"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.16650" test_ref="oval:org.mitre.oval:tst:100702"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22610" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0312) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0312"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0324.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:55.818-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.501-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:29.005-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22610 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:39.755-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:25.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22607" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0305) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0305"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0299 and CVE-2014-0311.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:59:02.169-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.308-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:28.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22607 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:10.316-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:25.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP 32 bit and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6512" test_ref="oval:org.mitre.oval:tst:99906"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP x64 / 2k3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5294" test_ref="oval:org.mitre.oval:tst:100280"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21371" test_ref="oval:org.mitre.oval:tst:100174"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19041" test_ref="oval:org.mitre.oval:tst:100257"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23330" test_ref="oval:org.mitre.oval:tst:100536"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22604" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0299) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0299" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0299"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0305 and CVE-2014-0311.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:47.323-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.103-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:28.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22604 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:38.193-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:25.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP 32 bit and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6512" test_ref="oval:org.mitre.oval:tst:99906"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP x64 / 2k3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5294" test_ref="oval:org.mitre.oval:tst:100280"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21371" test_ref="oval:org.mitre.oval:tst:100174"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19041" test_ref="oval:org.mitre.oval:tst:100257"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23330" test_ref="oval:org.mitre.oval:tst:100536"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22587" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0302) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0302"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0303.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:49.310-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:35.920-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:27.926-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22587 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:40.106-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:24.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP 32 bit and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6512" test_ref="oval:org.mitre.oval:tst:99906"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP x64 / 2k3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5294" test_ref="oval:org.mitre.oval:tst:100280"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21371" test_ref="oval:org.mitre.oval:tst:100174"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19041" test_ref="oval:org.mitre.oval:tst:100257"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23330" test_ref="oval:org.mitre.oval:tst:100536"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22581" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0303) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0303"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0302.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:59:07.166-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:35.609-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:27.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22581 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:36.500-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:24.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP 32 bit and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6512" test_ref="oval:org.mitre.oval:tst:99906"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP x64 / 2k3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5294" test_ref="oval:org.mitre.oval:tst:100280"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21371" test_ref="oval:org.mitre.oval:tst:100174"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19041" test_ref="oval:org.mitre.oval:tst:100257"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23330" test_ref="oval:org.mitre.oval:tst:100536"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22559" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0285) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0285"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0286.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:12.246-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:48.643-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:33.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22559 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:28.817-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:24.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6498" test_ref="oval:org.mitre.oval:tst:100192"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5281" test_ref="oval:org.mitre.oval:tst:100478"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21366" test_ref="oval:org.mitre.oval:tst:100587"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19016" test_ref="oval:org.mitre.oval:tst:100315"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23303" test_ref="oval:org.mitre.oval:tst:100212"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22546" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0267) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0267"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0289 and CVE-2014-0290.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:38.512-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:48.389-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:33.396-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22546 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:31.879-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:23.666-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="either os">
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22516" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0278) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0278" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0278"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0277 and CVE-2014-0279.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:49.233-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:47.166-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:30.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22516 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:30.189-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:23.442-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
          <criteria operator="AND" comment="vista/2008/versions">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="win7/2008 r2/version">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="xp/2003/version">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22514" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0304) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0304"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:43.522-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:29.950-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:26.517-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22514 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:36.679-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:23.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22512" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0298) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0298" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0298"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:53.469-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:29.751-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:26.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22512 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:39.129-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:23.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22510" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0286) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0286"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0285.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:53.512-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:46.845-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:29.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22510 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:30.876-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.710-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6498" test_ref="oval:org.mitre.oval:tst:100192"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5281" test_ref="oval:org.mitre.oval:tst:100478"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21366" test_ref="oval:org.mitre.oval:tst:100587"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19016" test_ref="oval:org.mitre.oval:tst:100315"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23303" test_ref="oval:org.mitre.oval:tst:100212"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22509" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0284) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0284"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:03.062-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:46.715-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:29.285-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22509 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:29.817-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.500-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22508" version="3" class="vulnerability">
      <metadata>
        <title>DirectShow Memory Corruption Vulnerability - CVE-2014-0301 (MS14-013)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0301" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0301"/>
        <description>Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG image, aka "DirectShow Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T12:04:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T11:01:15.482-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:29.038-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:26.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win XP and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of qedit.dll is less than 6.5.2600.6512" test_ref="oval:org.mitre.oval:tst:100735"/>
        </criteria>
        <criteria operator="AND" comment="XP x64 / 2k3(all) and vulnerable file version">
          <criteria operator="OR" comment="XP X64 / 2K3">
            <extend_definition comment="Microsoft Windows XP SP2 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:1799"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of qedit.dll is less than 6.5.3790.5294" test_ref="oval:org.mitre.oval:tst:100416"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.19033" test_ref="oval:org.mitre.oval:tst:100900"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.6002.23000" test_ref="oval:org.mitre.oval:tst:81807"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.23321" test_ref="oval:org.mitre.oval:tst:100852"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.18386" test_ref="oval:org.mitre.oval:tst:100823"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.7601.22000" test_ref="oval:org.mitre.oval:tst:81771"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.22590" test_ref="oval:org.mitre.oval:tst:100871"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.16812" test_ref="oval:org.mitre.oval:tst:100903"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.9200.20000" test_ref="oval:org.mitre.oval:tst:81492"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.20931" test_ref="oval:org.mitre.oval:tst:100638"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          </criteria>
          <criterion comment="Check if the version of qedit.dll is less than 6.6.9600.16650" test_ref="oval:org.mitre.oval:tst:100729"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22500" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0308) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0308"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0312, and CVE-2014-0324.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:59.228-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:28.730-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:25.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22500 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:08.759-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.236-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22497" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0313) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0313"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0321.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:59:05.170-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:28.613-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:25.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22497 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:08.558-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.030-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22481" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0288) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0288" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0288"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0274.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:00.731-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:46.283-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:28.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22481 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:32.038-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:21.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22472" version="5" class="vulnerability">
      <metadata>
        <title>Type Traversal Vulnerability (CVE-2014-0257) - MS14-009</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0257"/>
        <description>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers to execute arbitrary code via (1) a crafted web site or (2) a crafted .NET Framework application that exposes a COM server endpoint, aka "Type Traversal Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-18T02:39:12">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:22:25.792-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:45.622-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:27.275-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22472 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:32.297-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:21.340-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/xp/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.3655" test_ref="oval:org.mitre.oval:tst:99855"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.4247" test_ref="oval:org.mitre.oval:tst:100462"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
            <criterion comment="Check if the version is mscorlib.dll less than 2.0.50727.6413" test_ref="oval:org.mitre.oval:tst:100289"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.5477" test_ref="oval:org.mitre.oval:tst:100730"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win xp.server 2003/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.2034" test_ref="oval:org.mitre.oval:tst:100290"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81701"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.1022" test_ref="oval:org.mitre.oval:tst:100576"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19132" test_ref="oval:org.mitre.oval:tst:100509"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18063" test_ref="oval:org.mitre.oval:tst:100363"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19455" test_ref="oval:org.mitre.oval:tst:100693"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18449" test_ref="oval:org.mitre.oval:tst:100689"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2504" test_ref="oval:org.mitre.oval:tst:100537"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 and Win Vista / 7 / 2008 / 2008R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18444" test_ref="oval:org.mitre.oval:tst:100309"/>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 and Win 8 / Server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19455" test_ref="oval:org.mitre.oval:tst:100693"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18449" test_ref="oval:org.mitre.oval:tst:100689"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="ldr and gdr range">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.34011" test_ref="oval:org.mitre.oval:tst:100652"/>
            <criteria operator="AND" comment="ldr range for mscorlib.dll">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.36013" test_ref="oval:org.mitre.oval:tst:100709"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equals to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:100679"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8000" test_ref="oval:org.mitre.oval:tst:100668"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22465" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2014-0268) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0268"/>
        <description>Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-key creation, which allows remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:47.741-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:45.286-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:26.583-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22465 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:42.271-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:20.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22464" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0287) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0287"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0281.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:16.989-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:45.128-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:26.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22464 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:39.341-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:20.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22456" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft graphics component memory corruption vulnerability (CVE-2014-0263) - MS14-007</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0263"/>
        <description>The Direct2D implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a large 2D geometric figure that is encountered with Internet Explorer, aka "Microsoft Graphics Component Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T09:14:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-14T13:03:37.279-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:09.304-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:36.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22456 - Corrected criteria associated with Windows 7 and 2008 R2" date="2014-04-18T14:40:00.222-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-18T14:43:26.446-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:15.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 7 / Server 2008 R2 and File">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable File and Version">
            <criteria operator="AND" comment="gdr range">
              <criterion comment="Check if the version of D2d1.dll is greater than or equal to 6.1.7601.18000" test_ref="oval:org.mitre.oval:tst:113317"/>
              <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.16765" test_ref="oval:org.mitre.oval:tst:99737"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of D2d1.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:100095"/>
              <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.20883" test_ref="oval:org.mitre.oval:tst:99460"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / Server 2012 and File">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable file version">
            <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.16765" test_ref="oval:org.mitre.oval:tst:99737"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of D2d1.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:100095"/>
              <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.20882" test_ref="oval:org.mitre.oval:tst:99865"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1 / Server 2012 R2 and File">
          <criteria operator="OR" comment="Either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of D2d1.dll is less than 6.3.9600.16473" test_ref="oval:org.mitre.oval:tst:100215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22443" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0281) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0281"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0287.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:34.694-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:44.528-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:25.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22443 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:40.371-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:19.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22434" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability, a different vulnerability than CVE-2014-0404</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0406"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:45.576-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:27.944-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:09.043-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22413" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0289) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0289" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0289"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0267 and CVE-2014-0290.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:07.897-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.980-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:24.387-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22413 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:37.718-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:19.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="either os">
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22409" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5892"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:03:17">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-30T14:49:20.533-05:00">DRAFT</status_change>
            <status_change date="2014-02-17T04:01:38.405-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:43.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:100260"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.4" test_ref="oval:org.mitre.oval:tst:100012"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22399" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0309) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0309"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:59:04.188-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:24.054-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:24.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22399 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:10.864-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:19.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22398" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0283) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0283"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:01.775-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.546-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:23.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22398 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:37.827-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:19.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="either os">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="gdr/ldr">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
          <criteria operator="AND" comment="ldr range">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
          </criteria>
        </criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22391" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability, a different vulnerability than CVE-2014-0406</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0404"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:45.953-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:27.690-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:07.094-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22385" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0273) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0273" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0273"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0274, and CVE-2014-0288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:06.923-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.202-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:23.536-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22385 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:41.861-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:18.846-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22381" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0269) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0269"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:45.486-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.015-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:23.285-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22381 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:42.804-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:18.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6498" test_ref="oval:org.mitre.oval:tst:100192"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5281" test_ref="oval:org.mitre.oval:tst:100478"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"