CVE-2016-3405 covers multiple unspecified vulnerabilities in Zimbra Collaboration before 8.7.0, also referenced as bugs 103961 and 104828. NVD rates the issue as high severity with a network-reachable attack path, no privileges, no user interaction, and high integrity impact. The practical defensive takeaway is straightforward: systems running Zimbra Collaboration Suite 8.6.0 and earlier should be treated [truncated]
CVE-2016-3404 is a high-severity vulnerability in Zimbra Collaboration that can let remote attackers affect integrity through unspecified vectors. The public record does not describe the root cause or attack path, but the issue is treated as network-reachable and requires no privileges or user interaction. Use the vendor's 8.7.0 release materials and security advisories as the remediation context.
CVE-2016-3402 is a high-severity Zimbra Collaboration issue that can let a remote attacker affect confidentiality in versions before 8.7.0. The NVD record indicates network access, no privileges, and no user interaction are required, but the public record does not describe the exact attack path. The vendor-linked release notes and security advisories point to 8.7.0 as the relevant fixed release.
CVE-2016-3401 is an unspecified vulnerability in Zimbra Collaboration that can let a remote authenticated user affect integrity in versions before 8.7.0. The CVE record identifies it as bug 99810 and the NVD entry rates it as a network-reachable issue with high integrity impact but no confidentiality or availability impact. The linked Zimbra release notes and security advisory pages are the primary mitiga [truncated]